
Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499)
Disclaimer: This document is written purely for educational and security research purposes. All testing was performed on my own device. I am not responsible for bricked devices, data loss, or misuse of this information. The vulnerabilities discussed here are already publicly disclosed and patched. Do not attempt this on devices you do not own.
| File | Description |
|---|---|
| GBL-AutoRoot.bat | One-click exploit automation tool (Windows) |
How to use:
GBL-AutoRoot.bat from the link aboveCompatible with any Qualcomm ABL device affected by CVE-2026-24088. If your device returns
OKAY, root access is granted automatically.
This tool targets the Qualcomm ABL vulnerability (CVE-2026-24088). If your device has a vulnerable SoC and hasn't received the patched firmware yet, this tool will work.
| Status | Device / SoC Family | Example Devices |
|---|---|---|
| 🟢 Confirmed | Snapdragon 695 (SM6375) | POCO M7 Plus 5G, Redmi 15 5G |
| 🟡 Potential | Snapdragon 8 Gen 3 (SM8650) | Xiaomi 14 / Pro / Ultra, Redmi K70 Pro |
| 🟡 Potential | Snapdragon 8 Gen 2 (SM8550) | Xiaomi 13 / Pro, POCO F5 Pro, Redmi K60 Pro |
| 🟡 Potential | Snapdragon 8+ Gen 1 (SM8475) | Xiaomi 12T Pro, POCO F5 |
| 🟡 Potential | Snapdragon 888 (SM8350) | Mi 11, Mi 11X Pro, POCO F3 |
| 🟡 Potential | Snapdragon 7+ Gen 3 (SM7675) | POCO F6 |
| 🟡 Potential | Snapdragon 7 Gen 3 (SM7550) | Xiaomi Civi 4 |
| 🟡 Potential | Snapdragon 695 5G (SM6375) | POCO X4 Pro 5G, Redmi Note 11 Pro 5G |
| 🟡 Potential | Snapdragon 680 (SM6225) | Redmi Note 11, Redmi 10C |
| 🟡 Potential | Snapdragon 662 (SM6115) | POCO M3, Redmi 9T |
| 🔴 No Support | MediaTek (MTK) | POCO X6 Neo, Redmi Note 13 Pro+ |
| 🔴 No Support | Patched Firmware | HyperOS 3.0.304.0+ (Security Patch applied) |
📝 Community Testing Required: I do not have all these devices available for testing. If you have one of the "Potentially Supported" devices, please test the tool and let me know the results. This will help me confirm and officially add your device to the "Confirmed Working" list!
| Field | Value |
|---|---|
| Device | Poco M7 Plus 5G (codename: spring) |
| Chipset | Qualcomm SM6375 (Snapdragon 6s Gen 3) |
| Architecture | AArch64, KASLR enabled |
| SELinux | Enforcing (before exploit) |
| Bootloader | LOCKED |
| Test Platform | Windows 11, ADB Platform Tools |
| HyperOS Version | Kernel Version | GhostLock Result | GBL Exploit Result |
|---|---|---|---|
| 2.0.202.0 | 6.1.118-android14-11-ga3b9c44908dd-ab13320413 | ❌ Kernel Panic | ✅ Working |
| 2.0.208.0 | 6.1.138-android14-11-g51f8c580613d-ab13911623 | ❌ Kernel Panic | ✅ Working |
Research Note: I initially tested on HyperOS 2.0.202.0 where GhostLock caused kernel panic. I then updated to 2.0.208.0 to check if the newer kernel build (6.1.118 -> 6.1.138) would resolve GhostLock instability. The panic persisted - both builds share the same 6.1
pselect/fd_setinternal layout that GhostLock cannot handle. The GBL exploit worked on both versions.
During this research, I tested two independent exploit paths to achieve temporary root on this device without unlocking the bootloader:
| Approach A: GBL Exploit | Approach B: GhostLock | |
|---|---|---|
| Layer | Bootloader (ABL/fastboot) | Kernel (Linux 6.1) |
| CVE | CVE-2026-24088 | CVE-2026-43499 |
| Result on this device | ✅ Working | ❌ Kernel Panic |
| Root Type | Temporary (tethered) | Temporary (tethered) |
| Requires ADB? | Yes (fastboot mode) | Yes (shell access) |
| Kernel version sensitive? | No | Yes - only stable on 6.6-6.12 |
The GBL exploit worked. GhostLock failed with a kernel panic due to a kernel version mismatch. Both findings are documented in detail below.
CVE-2026-24088 affects Qualcomm's Android Boot Loader (ABL) across multiple devices.
Jan 2026 -> Vulnerability discovered during ABL unpacking & analysis
Feb 2026 -> Qualcomm patches: QcomModulePkg: Fix propagation of untrusted input into kernel cmdline
Mar 2026 -> Public PoC released; Xiaomi begins rolling out HyperOS 3.0.304.0 (patched)
Jun 2026 -> CVE-2026-24088 officially assigned in Qualcomm Security Bulletin
The exploit works as a three-stage chain at the bootloader level:
In Android 16, Qualcomm's ABL loads the Generic Bootloader (GBL) from the efisp partition. The critical flaw: ABL only checks if the binary is a valid UEFI application - it does NOT verify its cryptographic signature. This means a custom, unsigned UEFI application can be placed in efisp and it will execute at bootloader stage with full privileges.
The fastboot oem set-gpu-preemption command lacks input sanitization. The ABL directly concatenates the provided argument into the kernel command line without filtering.
By passing androidboot.selinux=permissive as an additional argument:
fastboot oem set-gpu-preemption 0 androidboot.selinux=permissive
...the bootloader writes androidboot.selinux=permissive into the kernel cmdline, which Android's init process reads at boot - effectively disabling SELinux enforcement.
A custom UEFI application placed in efisp can set is_unlocked and is_unlocked_critical flags to permanently unlock the bootloader. (This step was NOT tested - carries hard brick risk.)
⚠️ Stop before proceeding: Run the patch check in Section 7 first. If your device is patched, none of this will work.
Prerequisites: