Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/bobikl/cve-2026-43499-t807d
Android SecurityPrivilege EscalationMemory ForensicsExploitationReverse EngineeringPost-ExploitationMobile SecurityPapers & ResearchPayload DevelopmentBinary Exploitation
GitHub
241 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
bobikl/cve-2026-43499-t807d

CVE-2026-43499-T807D

Android kernel exploit research package for CVE-2026-43499, containing popsicle exploit source, embedded su payload, root bridge helper, and reproducible build artifacts.

View Repository

T807D Final Artifacts — Source One-to-One Correspondence Recovery Package

Generated: 2026-08-08

Conclusion

This directory has organized the complete popsicle source tree, necessary header files, embedded su payload, production binaries, and runtime scripts that can be recovered from the current project.

A distinction must be made:

  1. The production binaries of r562 SO and r557 helper are fully preserved, and their hashes can be verified.
  2. The project has not preserved the old source snapshots, object files, or complete build artifacts with DWARF from before these two production binaries were compiled. Therefore, the current source cannot be honestly labeled as "byte-for-byte the source from which the production binaries were compiled at the time."
  3. The currently preserved source is the only complete popsicle source tree in the Kit, and is also the maintenance baseline after the 2026-08-05 review.

Directory Structure

source-final-correspondence-20260808/
├─ source/
│  ├─ exploit/
│  │  ├─ popsicle/
│  │  │  ├─ main.c
│  │  │  ├─ util.c
│  │  │  ├─ slide.c
│  │  │  ├─ fops.c
│  │  │  ├─ pipe.c
│  │  │  ├─ preload.c
│  │  │  ├─ root_bridge_helper.c
│  │  │  ├─ su_blob.S
│  │  │  ├─ su_daemon.c
│  │  │  ├─ common.h / offset.h / target.h
│  │  │  ├─ kernelsnitch/
│  │  │  └─ build/embed/su_daemon_aarch64_pie
│  │  └─ ghostlock-oneplus/kernelsnitch/
│  └─ target-files/popsicle-target.h
├─ embed/su_daemon_aarch64_pie
├─ artifacts/production/
├─ runtime/
├─ review-build/
├─ rebuild-current-source.ps1
├─ source-files.sha256
├─ binary-function-size-diff.md
├─ binary-function-size-diff.csv
└─ manifest.json

One-to-One Correspondence

r562 preload SO

Production file:

artifacts/production/t807d-popsicle-r562-show-callback-canonical-20260804.so

SHA-256:

B6DED21F90096A2FA2567807F79E7E8CCFDF9802DAF4628277A333DD8FE7DB71

Main source inputs:

Production ObjectCorresponding Source
SO main flowsource/exploit/popsicle/main.c
Common kernel and userspace utilitiessource/exploit/popsicle/util.c
slide and address locationsource/exploit/popsicle/slide.c
fops and pselect trigger pathsource/exploit/popsicle/fops.c
pipe, reclaim, direct writesource/exploit/popsicle/pipe.c
LD_PRELOAD entry and su file writesource/exploit/popsicle/preload.c
Embedded su boundary symbolssource/exploit/popsicle/su_blob.S
Common definitionscommon.h, offset.h, target.h
Target configurationsource/target-files/popsicle-target.h
KernelSnitch headerssource/exploit/popsicle/kernelsnitch/ and source/exploit/ghostlock-oneplus/kernelsnitch/
Embedded file contentsource/exploit/popsicle/build/embed/su_daemon_aarch64_pie

r557 root bridge helper

Production file:

artifacts/production/t807d-root-bridge-helper-r557-show-verify-callback-20260804

SHA-256:

F7FF4C293902993183F98A8D314FA2ECD012A72A36F287A361C4503844EAAB91

Main source inputs:

Production ObjectCorresponding Source
root bridge, marker, cred, SELinux, KSU auxiliary logicsource/exploit/popsicle/root_bridge_helper.c
Embedded su boundary symbolssource/exploit/popsicle/su_blob.S
su contentsource/exploit/popsicle/build/embed/su_daemon_aarch64_pie
Common definitions and target configurationSame as r562

Runtime Scripts

  • r562-show-stream.sh: Loads the production parameters of the r562 SO.
  • r571-current-helper-cred-stream.sh: r571/r572 temporary root chain.
  • r572-current-helper-cred-no-ksu.sh: Temporary root stage without KSU integration.
  • r572-wrapper.sh: helper environment wrapper.
  • r575-selinux-rmw-safe.sh: SELinux RMW stage.
  • r575-selinux-rmw-wrapper.sh: r575 wrapper.
  • r573, r575, ksu-* files in artifacts/production: Copies of the scripts actually used in the final directory.

Correspondence Verification Performed

Source Tree Completeness

Two easily overlooked relative path dependencies have been filled in.

First, target.h references:

#include "../../target-files/popsicle-target.h"

Therefore the source must maintain:

source/exploit/popsicle/target.h
source/target-files/popsicle-target.h

Second, popsicle/kernelsnitch/utils.h and kernelsnitch.h continue to reference:

../../ghostlock-oneplus/kernelsnitch/...

Therefore source/exploit/ghostlock-oneplus/kernelsnitch/ must also be preserved.

Copying only source/popsicle would yield an incomplete snapshot that "looks complete but actually cannot compile." This recovery package has been organized according to the original relative path layout.

Current Source Recompilation

Toolchain:

NDK: D:Android

dk 29android-ndk-r29 API: 35 ABI: AArch64

Execute:

powershell.exe -NoLogo -NoProfile -ExecutionPolicy Bypass -File .

ebuild-current-source.ps1

Current source recompilation results:

FileSizeSHA-256
review-build/rebuild-current-source.so139600D5C8CF6D3A0A223F0BB3319FFAE926EF3EDF56DEF520B0A99CF7526B4437EC1A
review-build/rebuild-current-source-helper75008025FD4BEB793227D9595D5739483798BBB8CDB94B69734399BE4C9F329032D8F

This proves the source tree is compilable, but it cannot replace the verified production binaries in artifacts/production.

Why the Current Source Cannot Be Reproduced Byte-for-Byte with r562/r557

Timeline evidence:

ObjectFile Time
r557 helper production file2026-08-04 22:47:29
r562 SO production file2026-08-04 22:59:05
main.c2026-08-04 22:22:16
slide.c2026-08-04 21:54:58
common.h2026-08-05 08:07:26
pipe.c2026-08-05 08:07:34
preload.c2026-08-05 08:07:30
root_bridge_helper.c2026-08-05 08:10:10
util.c2026-08-05 08:14:57

At least the current contents of common.h, pipe.c, preload.c, root_bridge_helper.c, and util.c were written to disk or modified after the two production binaries were generated.

The project also did not find:

  • The old source directories corresponding to r562/r557;
  • The corresponding .o, .bc, .ll, .d build intermediate files;
  • DWARF debug information with source line numbers;
  • The complete commands, compiler switches, and source file hash lists that could reproduce the production build.

Therefore, based on the available materials, what can be done is to recover all usable source and locate the differences; it is not possible to reverse the production ELF back into the byte-for-byte C source from that time.

Binary Function-Level Differences

binary-function-size-diff.md provides the function size differences between the production files and the current source recompilation files.

Key differences in the r562 SO:

  • cleanup_page_prepare_state
  • prepare_good_kernel_page
  • direct_pselect_write_once_internal
  • write_embedded_su_file

Key differences in the r557 helper:

  • install_su_daemon
  • pselect_install_task_creds
  • pselect_marker_only
  • pselect_direct_cred_worker
  • copy_env_path newly added in the current source

These differences are consistent with the fix directions recorded in the Round592 source review: environment variable path copying, independent linker symbol address differences, allocation failure handling, reclaim cleanup, etc.

Final Usage Recommendations

  • To reproduce the already-verified device chain: use the production binaries in artifacts/production.
  • To continue modifying the source: use source/ as the current maintenance baseline.
  • To audit provenance and hashes: check manifest.json, source-files.sha256, and binary-function-size-diff.md.
  • Do not rename the review-build results to r562/r557; that would confuse the production rollback points and source provenance.

The complete source hashes are in source-files.sha256. The hashes of production artifacts, scripts, embedded files, and review build results are in manifest.json.

This Recompilation Test

Download Tool