Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/creeeeger/cve-2024-56426
Embedded Systems SecurityPrivilege EscalationExploitationReverse EngineeringMobile SecurityHardware SecurityPayload DevelopmentFirmware AnalysisBinary Exploitation
GitHubcreeeeger/cve-2024-56426

CVE-2024-56426

A PoC of the CVE-2024-56426 vulnerability.

View Repository
167246 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exynos 990 / Exynos9830 Unified BootROM Exploit

Unified CVE-2024-56426 tooling for the Exynos 990 Galaxy S20, S20 FE, and Note20 families. The exploit accepts all ten model names and maps them onto six verified stock bootloader families.

[!CAUTION] The tracked key bundle and generated images are fusing-capable. Fusing is irreversible. A phone fused to a key can only boot images compatible with that key. A wrong model, rollback revision, patch set, or key bundle can leave the device in a fused boot loop. Use development keys and the UFS payload while iterating. Add --no-fuse to every preparation/signing command unless custom-key fusing is explicitly intended.

Supported Models

The selected model controls both the BL1 model ID and the exact-model LK patch TSV. Runtime artifact controls which stock firmware and encrypted split images are used by preflight. The four non-5G flags that use paired 5G runtime artifacts also patch LK's model-ID check and model-ID programming path.

[!IMPORTANT] On the stock firmware builds listed below, G780F, N980F, N981B, N985F, and N986B cannot use the UH-to-BOOTLOADER method to enter EUB. Their LK bootloaders call Check_signinfo(), which compares the image's embedded BinaryName (uh.bin) with the BOOTLOADER partition's expected filename (sboot.bin). The mismatch produces Binaryname has changed (uh.bin) -> (sboot.bin) and rejects the flash.

Use the appropriate model-specific test points to enter EUB on these devices instead of the UH method.

Model flagRuntime artifactRuntime firmwareModel IDEVTRollbackTestedUH method / EUB entry
G780FG780FG780FXXSOFYJ10x1541124❌Blocked — use test points
G980FG981BG981BXXSNHYB10x1431123✅No filename block
G981BG981BG981BXXSNHYB10x13D1123❌No filename block
G985FG986BG986BXXSNHYB10x1421123✅No filename block
G986BG986BG986BXXSNHYB10x13C1123✅No filename block
G988BG988BG988BXXSNHYB10x13E1123❌No filename block
N980FN981BN981BXXSIHYH30x1531118❌Blocked — use test points
N981BN981BN981BXXSIHYH30x14E1118❌Blocked — use test points
N985FN986BN986BXXSIHYH30x1521118❌Blocked — use test points
N986BN986BN986BXXSIHYH30x14D1118❌Blocked — use test points

Exynos 990 KVM and EL2 mode

All ten supported Galaxy S20, S20 FE, and Note20 model flags have an opt-in CLI-only KVM boot profile. Build a branch of the Exynos 990 kernel whose name contains kvm, and add --kvm to the exact-model command, for example:

python3 exploit/exploit.py --build-sboot --model G985F --no-fuse --kvm

This profile removes the LK H-Arx/UH path, asks EL3 to enter the kernel at EL2, and applies the matching decrypted/re-encrypted EL3 monitor patch table. It remains unavailable for stock/tampered bootloader flash modes. The web control center intentionally has no KVM control. With the matching kernel and WindowsInQemu, Windows can run in QEMU on the phone with full speed via KVM.

Quick Start

Do not treat every mode as one numbered installation sequence. Choose a goal:

GoalPath
Install a signed custom ROMExact model/setup → EUB → temporary --signed --no-fuse chain → flash the ROM's complete signed output → UFS first boot
Test the exploitOptional --prepare --no-fuse → EUB → --signed --no-fuse → stop
Develop the boot chain (CLI only)Temporary no-fuse test → build → flash generated SBoot/TZSW/LDFW → UFS
Dump / recoveryUse its separate workflow and fuse-state checks

--prepare performs host-only preparation: it replaces generated working images and builds and signs local files, without opening USB. It is not a read-only dry-run or a required predecessor: --signed repeats preflight. The generated three-part Heimdall command is a boot-chain development tool; it is not a custom-ROM flash.

Read USER_GUIDE.md and choose its matching workflow before touching a device. It includes the complete-ROM handoff plus the unfused, fused, and uncertain-state recovery rules.

Optional Local UI

The browser UI's HTTP server uses Python's standard library and calls the existing exploit/exploit.py CLI. Key-bundle validation and tool execution also require the packages in requirements.txt. Boot-chain development and its generated three-part Heimdall command remain terminal-only tools.

Start it from the repository root:

python3 exynos990_control_center.py

The launcher binds to 127.0.0.1, generates a new access token, prints the full local URL, and opens it in the default browser. Use --no-browser when a browser should not be opened automatically:

python3 exynos990_control_center.py --no-browser

The UI provides:

  • red/green dependency and repository-asset checks;
  • one global target-model choice and exactly two fuse decisions: Stay unfused or Fuse;
  • a workflow chooser that shows and numbers only the selected workflow's steps;
  • install-ROM, exploit-test, BootROM-dump, and stock-recovery workflows;
  • an exact-model tampered-loader action that validates UH and flashes it to the BOOTLOADER slot with Heimdall to enter EUB;
  • a permanent fuse warning and the configured key/eFuse SHA-256 fingerprint;
  • an unfused-only stock boot-chain restore card that is unavailable after choosing Fuse;
  • live process output, cancellation, and per-stage verification markers.

It also shows a CLI-only Exynos 990 KVM notice, but deliberately does not expose a KVM option or forward --kvm to any web action.

USB access follows the permissions of the process that launched the control center. Configure the supplied udev/driver permissions before starting it. The UI does not request, retain, or forward privilege credentials. Keep the printed token URL private and stop the server immediately after use.

Terminal users can ignore exynos990_control_center.py; every CLI command documented below remains unchanged and fully supported.

Requirements

Python 3.10 or newer is required.

Windows 10/11 (native PowerShell):

.\windows\setup.ps1
. .\windows\activate.ps1
python .\exploit\exploit.py --prepare --model G985F --no-fuse
Download Tool