
One-click temporary KernelSU root (late-load) for Samsung Galaxy via DirtyFrag (CVE-2026-43284). No Shizuku/PC/ADB.
한국어 · English
One-click temporary KernelSU root (late-load) for Samsung Galaxy devices
via the DirtyFrag (CVE-2026-43284) exploit.
No Shizuku, no PC, no ADB — the app performs everything from the exploit to KernelSU late-load by itself.
⚠️ WARNING
I am not responsible for bricked phones.
- This tool uses a temporary (late-load) root and does not flash any partition, so it does not trip the KNOX warranty bit.
- It works on DirtyFrag-vulnerable kernels. On a non-vulnerable or incompatible kernel it stops at the patch/primitive verification step and does not proceed to root acquisition.
- Only run this on a device you own.
- While root is active, some apps (banking / government / DRM) may detect root and refuse to run.
- No warranty; use at your own risk.
The app selects a kernel module (KO) automatically based on the Android KMI family (androidNN) and the
kernel major.minor shown by uname.
androidNNis not necessarily the same as the Android version number you see; it means the Android kernel / KMI family shown byuname -r.
Measured results so far:
| Device | Model | Kernel | Result |
|---|---|---|---|
| Galaxy Z Fold8 Ultra | SM-F976N (q8q) | 6.12.58-android16 | ✅ works (baseline) |
| Galaxy S25 | SM-S931N (pa1q) | 6.6.98-android15 | ✅ works |
| Galaxy S24+ | SM-S926N (e2s) | 6.1.157-android14 | ❌ CBC primitive NO-OP |
major.minor, but whether the kernel primitive DirtyFrag needs actually
exists and works.6.6.98-android15 and 6.12.58-android16; on 6.1.157-android14 the CBC primitive
was a NO-OP and it did not work.android12-5.10
android13-5.10
android13-5.15
android14-5.15
android14-6.1
android15-6.6
android16-6.12
android17-6.18
A KO for each KMI above is bundled. This does not guarantee operation on every target device/firmware.
Modules can only be installed after root is acquired. Follow the order below.
After step 4 the app auto-checks modules and, if missing, shows a "Module installation required" notification (+ an "Open manager" button). In KernelSU manager → Modules, install Zygisk-Next and LSPosed (zip).
Return to the app — it is auto-detected (no need to press ROOT again). Once modules are ready, a "Soft restart required (for LSPosed to work)" notification appears.
Tap [Soft restart now] in the notification, or press 소프트 재시작 (SOFT RESTART) in the app. When done, the state becomes Fully Activated.
Optionally enable Auto-root on boot to re-apply root automatically after each reboot.
Summary: root → install modules (notification-guided) → auto-detect → soft restart (notification / one tap). Rooting still completes even without modules; instead of a hard failure the app provides notifications, guidance, and a one-tap action.
su context.system_server pid (logcat + lspd verbose,
mtime-guarded), eliminating false positives/negatives.Enforcing without a reboot after root + Zygisk + LSPosed are confirmed.Enable Auto-root on boot. After a reboot a foreground service runs exploit → su → module stage
automatically and shows progress notifications.
Auto soft restart defaults to OFF (to avoid loops). When LSPosed activation is needed, run a soft restart once in the app.
CBC page-cache primitive is a NO-OP ... Aborting..ksud unload is never used (it hard-locks the device).| First-run rooting | Soft restart |
|---|---|
![]() | ![]() |
Animated WebP — plays automatically. (Click to view full size.)