Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
GhostLock-for-OnePlus15T — (CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T. | Kitploit
Tools/GitHubGitHub/cuteaplane/ghostlock-for-oneplus15t
Android SecurityPrivilege EscalationVulnerability AnalysisExploitationMobile SecurityPayload DevelopmentBinary Exploitation
GitHubcuteaplane/ghostlock-for-oneplus15t

GhostLock-for-OnePlus15T

(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.

View Repository
121682 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

GhostLock — OnePlus 15T

中文

Kernel exploit targeting locked-bootloader OnePlus 15T devices. Uses CVE-2026-43499 to obtain root access without unlocking the bootloader or modifying boot.img.

Authorized security research and educational purposes only.

Modified from the original GhostLock-for-OnePlus repository, adapted for OnePlus 15T (PLZ110 / SM8850 / Snapdragon 8 Elite) physical memory layout and CPU timing.


Table of Contents

  • Vulnerability Overview
  • Supported Devices
  • Prerequisites
  • Building
  • Usage
  • Run Modes
  • Technical Details
  • File Structure
  • Adding New Devices
  • FAQ

Vulnerability Overview

ItemDetail
CVECVE-2026-43499
TypeFutex PI (Priority Inheritance) Use-After-Free
ScopeLinux kernel 2.6.39 ~ 7.1
Fixed inMainline 7.1 (commit 3bfdc63936dd)
Android StatusGKI 6.12.x still vulnerable

Root Cause

The pselect6 syscall copies fd_set to the kernel stack. When combined with the futex PI waiter mechanism, a freed stack frame can be reallocated as a rt_mutex_waiter struct. During PI chain traversal, rb-tree rebalancing writes controlled data to arbitrary kernel addresses.

Chain

futex PI UAF (CVE-2026-43499)
  ├─ Forge rt_mutex_waiter object
  ├─ Control kernel stack via pselect/select fd_set layout
  ├─ Trigger rt_mutex PI operation for arbitrary write
  ├─ Write 1: selinux_state.enforcing = 0
  └─ Write 2: cred → init_cred (uid=0, full capabilities)

Supported Devices

DeviceCodenameSoCKernelFirmwareStatus
OnePlus 15TPLZ110SM8850 (Snapdragon 8 Elite)6.12.38-android16-5-g844001fb8721-ab14552068-4kColorOS 16.0.9.400✅ Verified

For Ace 6T and OnePlus 15, see the original repository.


Prerequisites

ksud (Required for KernelSU)

GhostLock handles privilege escalation. KernelSU installation requires ksud (bundled with KMI-specific kernelsu.ko):

SourceNotes
ReSukiSU APK (recommended)Install ReSukiSU; the APK bundles libksud.so
CI ReleaseDownload from ReSukiSU CI (ksud-aarch64-linux-android.zip)

Without ksud, the exploit still gets uid=0 root shell, but KernelSU won't be installed and su won't persist.


Building

Prerequisites

  • Android NDK (r25+)
  • Set ANDROID_NDK_HOME or ANDROID_NDK_ROOT

Build

# Default (API 35)
make

# Specify API level
make API=34

# Specify NDK path
NDK=/path/to/android-ndk make

Artifact

ghostlock — statically linked ARM64 ELF executable.


Usage

One-time Setup

# 1. Enable ADB TCP mode
adb tcpip 5555

# 2. Push ADB key (required for bootstrap mode)
adb push ~/.android/adbkey /data/local/tmp/a/adbkey

# 3. Push the exploit
adb push ghostlock /data/local/tmp/a/e
adb shell chmod 755 /data/local/tmp/a/e

After first success, resetprop automatically sets persist.adb.tcp.port=5555, allowing fully automatic runs on subsequent reboots.


Run Modes

Full Exploit (ADB shell context)

/data/local/tmp/a/e
  • perf available, precise child task_struct leaking
  • Two-stage: W1 disable SELinux → W2 privilege escalation → KernelSU load

Bootstrap Mode (App context, seccomp restricted)

/data/local/tmp/a/e --bootstrap
  1. Write 1 → disable SELinux
  2. Use freed permissions to setprop enable ADB TCP 5555
  3. Built-in Mini ADB client connects to 127.0.0.1:5555
  4. RSA authentication with pre-pushed key
  5. Full exploit execution via ADB shell (no seccomp)

Write 1 Only

/data/local/tmp/a/e --write1
  • Up to 20 attempts
  • Useful for debugging or temporary SELinux disable

Technical Details

1. Runtime Kernel Matching

Offsets stored in src/devices/offsets.h lookup table, keyed by uname -r. Program auto-matches at startup; unknown kernels are rejected.

static const struct kernel_offsets known_offsets[] = {
  OFFSETS_ENTRY("6.12.38-android16-5-...-ab14275539-4k", ...),
  OFFSETS_ENTRY("6.12.38-android16-5-...-ab14552068-4k", ...),
  OFFSETS_ENTRY("6.12.23-android16-5-...-ab14541642-4k", ...),
  { .uname_r = NULL }  /* sentinel */
};

Offset Sources

TypeCountExtraction
kallsyms global symbols28tools/extract_target.py
BTF struct fields57tools/extract_btf.py
Derived values9Auto-calculated
Fixed constants12Hardcoded

BTF-verified Structs

StructFieldsPurpose
task_struct17Process descriptor, cred, seccomp
rt_mutex_waiter6UAF forge target
cred4Credentials, capabilities
seccomp3Seccomp filter state
pipe_inode_info11Pipe buffer operations
file_operations13Fake fops table
mm_struct1Memory descriptor owner

2. KASLR Bypass

SLIDE Mode — boot_id Leak

When kernel pointers are restricted (kptr_restrict), leak the base address via boot_id overwritten with a kernel address:

Read /proc/sys/kernel/random/boot_id
  └─ UUID contains nfulnl_logger address
      └─ KASLR slide = leaked_addr - image_offset
          └─ kaslr_base

FOPS/CFI Mode — fops Table Leak

When ashmem device is accessible, use configfs read/write primitives to read function pointers from the ashmem fops table and compute KASLR offset.

3. Kernel Heap Spray

Forge kernel objects on order-3 (32KB) pages:

  • Fake file_operations — hijack ashmem miscdevice fops pointer
  • Fake rt_mutex_waiter — simulate PI chain waiter node
  • Fake task_struct — task reference during PI traversal
  • Fake rt_mutex (lock) — correct waiter/owner information

Implemented via SKB (socket buffer) + KernelSnitch:

  • KernelSnitch — futex hash collision to leak mm_struct addresses
  • SKB spray — sendmsg to fill kernel heap

4. Physical Memory R/W (Pipe)

After obtaining KASLR base, use pipe buffers for physical-level memory access:

1. Locate pipe buffer in physmap
2. Forge pipe_buffer ops table pointing to known pipe_buf_ops
3. Hijack pipe_buffer.page to target physical address
4. Arbitrary physical read/write via normal pipe operations

Supported: pipe_read64, pipe_write64, pipe_phys_read_data, pipe_phys_write_data

5. Two-Stage Write

Write 1 — Disable SELinux

Target: selinux_state.enforcing (offset 0x00)
Method: child-node PI write → forge waiter __rb_parent_color
        pointing to selinux_enforcing - 8
        rb-tree rebalance writes 0x00

Write 2 — Escalate to Root

Target: child process cred pointer
Method: 1. fork child → perf_find_task() locate task_struct
        2. calculate cred field offset
        3. child-node PI write → cred = init_cred (uid=0, full caps)
        4. clear seccomp (TIF_SECCOMP + seccomp struct zeroed)

Capability readback verification is performed after cred overwrite.

6. Built-in Mini ADB Client

src/core/miniadb.c — lightweight ADB protocol client for bootstrap mode:

1. TCP connect 127.0.0.1:5555
2. A_CNXN → connection request
3. A_AUTH → RSA token challenge
4. dlopen("libcrypto.so") → PEM_read_bio_RSAPrivateKey → RSA_sign
5. A_AUTH (AUTH_SIGNATURE) → signed response
6. A_CNXN → connection established
7. A_OPEN "shell:/data/local/tmp/a/e" → full exploit

Supports SHA-1 and SHA-256 signature algorithms.


File Structure

Download Tool