
A PoC of the CVE-2024-56426 vulnerability.
Unified CVE-2024-56426 tooling for the Exynos 990 Galaxy S20, S20 FE, and Note20 families. The exploit accepts all ten model names and maps them onto six verified stock bootloader families.
[!CAUTION] The tracked key bundle and generated images are fusing-capable. Fusing is irreversible. A phone fused to a key can only boot images compatible with that key. A wrong model, rollback revision, patch set, or key bundle can leave the device in a fused boot loop. Use development keys and the UFS payload while iterating. Add
--no-fuseto every preparation/signing command unless custom-key fusing is explicitly intended.
The selected model controls both the BL1 model ID and the exact-model LK patch TSV. Runtime artifact controls which
stock firmware and encrypted split images are used by preflight. The four non-5G flags that use paired 5G runtime
artifacts also patch LK's model-ID check and model-ID programming path.
[!IMPORTANT] On the stock firmware builds listed below, G780F, N980F, N981B, N985F, and N986B cannot use the UH-to-BOOTLOADER method to enter EUB. Their LK bootloaders call
Check_signinfo(), which compares the image's embeddedBinaryName(uh.bin) with the BOOTLOADER partition's expected filename (sboot.bin). The mismatch producesBinaryname has changed (uh.bin) -> (sboot.bin)and rejects the flash.Use the appropriate model-specific test points to enter EUB on these devices instead of the UH method.
| Model flag | Runtime artifact | Runtime firmware | Model ID | EVT | Rollback | Tested | UH method / EUB entry |
|---|---|---|---|---|---|---|---|
G780F | G780F | G780FXXSOFYJ1 | 0x154 | 11 | 24 | ❌ | Blocked — use test points |
G980F | G981B | G981BXXSNHYB1 | 0x143 | 11 | 23 | ✅ | No filename block |
G981B | G981B | G981BXXSNHYB1 | 0x13D | 11 | 23 | ❌ | No filename block |
G985F | G986B | G986BXXSNHYB1 | 0x142 | 11 | 23 | ✅ | No filename block |
G986B | G986B | G986BXXSNHYB1 | 0x13C | 11 | 23 | ✅ | No filename block |
G988B | G988B | G988BXXSNHYB1 | 0x13E | 11 | 23 | ❌ | No filename block |
N980F | N981B | N981BXXSIHYH3 | 0x153 | 11 | 18 | ❌ | Blocked — use test points |
N981B | N981B | N981BXXSIHYH3 | 0x14E | 11 | 18 | ❌ | Blocked — use test points |
N985F | N986B | N986BXXSIHYH3 | 0x152 | 11 | 18 | ❌ | Blocked — use test points |
N986B | N986B | N986BXXSIHYH3 | 0x14D | 11 | 18 | ❌ | Blocked — use test points |
All ten supported Galaxy S20, S20 FE, and Note20 model flags have an opt-in
CLI-only KVM boot profile. Build a branch
of the Exynos 990 kernel
whose name contains kvm, and add --kvm to the exact-model command, for example:
python3 exploit/exploit.py --build-sboot --model G985F --no-fuse --kvm
This profile removes the LK H-Arx/UH path, asks EL3 to enter the kernel at EL2, and applies the matching decrypted/re-encrypted EL3 monitor patch table. It remains unavailable for stock/tampered bootloader flash modes. The web control center intentionally has no KVM control. With the matching kernel and WindowsInQemu, Windows can run in QEMU on the phone with full speed via KVM.
Do not treat every mode as one numbered installation sequence. Choose a goal:
| Goal | Path |
|---|---|
| Install a signed custom ROM | Exact model/setup → EUB → temporary --signed --no-fuse chain → flash the ROM's complete signed output → UFS first boot |
| Test the exploit | Optional --prepare --no-fuse → EUB → --signed --no-fuse → stop |
| Develop the boot chain (CLI only) | Temporary no-fuse test → build → flash generated SBoot/TZSW/LDFW → UFS |
| Dump / recovery | Use its separate workflow and fuse-state checks |
--prepare performs host-only preparation: it replaces generated working images and builds and signs local files,
without opening USB. It is not a read-only dry-run or a required predecessor: --signed repeats preflight.
The generated three-part Heimdall command is a boot-chain development tool; it is not a custom-ROM flash.
Read USER_GUIDE.md and choose its matching workflow before touching a device. It includes the complete-ROM handoff plus the unfused, fused, and uncertain-state recovery rules.
The browser UI's HTTP server uses Python's standard library and calls the existing exploit/exploit.py CLI.
Key-bundle validation and tool execution also require the packages in requirements.txt. Boot-chain development and
its generated three-part Heimdall command remain terminal-only tools.
Start it from the repository root:
python3 exynos990_control_center.py
The launcher binds to 127.0.0.1, generates a new access token, prints the full local URL, and opens it in the default
browser. Use --no-browser when a browser should not be opened automatically:
python3 exynos990_control_center.py --no-browser
The UI provides:
It also shows a CLI-only Exynos 990 KVM notice, but deliberately does not expose a KVM option or forward --kvm to any
web action.
USB access follows the permissions of the process that launched the control center. Configure the supplied udev/driver permissions before starting it. The UI does not request, retain, or forward privilege credentials. Keep the printed token URL private and stop the server immediately after use.
Terminal users can ignore exynos990_control_center.py; every CLI command documented below remains unchanged and fully
supported.
Python 3.10 or newer is required.
Windows 10/11 (native PowerShell):
.\windows\setup.ps1
. .\windows\activate.ps1
python .\exploit\exploit.py --prepare --model G985F --no-fuse