Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
K50G-POCOF4GT-CVE-2026-43499-PoC — Local privilege escalation exploit for Redmi K50G/POCO F4 GT using CVE-2026-43499 (futex UAF) to gain temporary root and load KernelSU without unlocking bootloader. | Kitploit
Tools/GitHubGitHub/cxyofficial/k50g-pocof4gt-cve-2026-43499-poc
Android SecurityPrivilege EscalationExploit FrameworksExploitationPost-ExploitationMobile SecurityPayload DevelopmentBinary Exploitation

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
cxyofficial/k50g-pocof4gt-cve-2026-43499-poc

K50G-POCOF4GT-CVE-2026-43499-PoC

Local privilege escalation exploit for Redmi K50G/POCO F4 GT using CVE-2026-43499 (futex UAF) to gain temporary root and load KernelSU without unlocking bootloader.

View Repository
861 month agoNot yet reviewed

Redmi K50 Gaming (ingres) — CVE-2026-43499 (GhostLock) Temporary Root PoC

One-click temporary Root without unlocking BL. Uses the GhostLock (CVE-2026-43499, futex PI Use-After-Free) local privilege escalation chain to obtain a root anchor, then mounts the kernelsu module into the running kernel via KernelSU 3.3.0 late-load, working with the KSU module to keep SELinux Permissive and fix networking.

Target device: Redmi K50G / POCO F4 GT — codename ingres, SoC SM8450 (Snapdragon 8 Gen 1) System: Android 14, UKQ1.240624.001, kernel 5.10.209-android12 (KMI android12-5.10) Status: ✅ Temporary Root verified working on real device


1. File Description

FilePurpose
exploitGhostLock privilege escalation binary (ARM64 PIE, not stripped). Internally contains KernelSnitch mm collision locating, futex PI UAF stack overwrite, kernel anchor root, su daemon, embedded libksud.so and KSU late-load logic
Root-K50G.batWindows one-click script (locates files relative to its own directory, double-click to use): detect device → push files → run privilege escalation → directly enter root shell
ksu_loader.shExecuted by the rooted kernel anchor: libksud.so late-load --kmi 5.10.209-android12 loads KernelSU, and sequentially triggers the post-fs-data / services / boot-completed stages
ksu-module/chuxin_permissive_netfix/KernelSU module (module.prop + service.sh): monitors enforce=0 every 2 seconds, and resets anti-tamper properties, restarts netd, enables wifi/data to fix network disconnection
adb/Built-in adb tools (portable, no installation required)
adb驱动无需重启.exeXiaomi driver one-click installation tool

2. Successful Method / Privilege Escalation Chain

The entire chain consists of four steps:

  1. GhostLock UAF trigger (CVE-2026-43499)
    • futex PI ring topology (FUTEX_WAIT_REQUEUE_PI + FUTEX_CMP_REQUEUE_PI) creates a dangling rt_mutex_waiter on the kernel stack;
    • Uses kernel stack stamps (sysctl paths, etc.) to overwrite the freed location with forged waiter fields;
    • The consuming thread triggers rt_mutex_adjust_prio_chain traversal, yielding controlled kernel read/write primitives.
  2. Kernel anchor root
    • Injects cred via the write primitive (uid/gid=0, full caps, kernel SID), obtaining a root anchor process (anchor: ROOT uid=0 in the run log);
    • Forks within the anchor: root shell (SHELL_ROOT=1) and su daemon (SU_DAEMON=1, /data/local/tmp/su).
  3. KernelSU late-load
    • The kernel module kernelsu.ko is loaded into the running kernel via libksud.so late-load --kmi 5.10.209-android12 (no flashing/patching boot image required, precisely matching the device's current KMI);
    • ksu_loader.sh sequentially executes post-fs-data, services, boot-completed, allowing the KernelSU management framework (ksud) to start up normally.
  4. Permissive retention + network fix
    • The KSU module chuxin_permissive_netfix is installed into /data/adb/modules/: its service runs in the ksu domain (with security:setenforce permission), writing enforce back to 0 every 2 seconds, counteracting ksud's behavior of flipping SELinux back to Enforcing after boot-completed (preventing AVC from rejecting su socket + network disconnection);
    • About 10s after first boot, resets ro.boot.flash.locked / verifiedbootstate / warranty bit properties and restarts netd, fixing networking after Root.

3. Usage

Method A: Windows one-click (recommended)

  1. Enable developer options + USB debugging on the phone, connect to the computer;
  2. Double-click Root-K50G.bat;
  3. Allow USB debugging authorization on the phone as prompted;
  4. Privilege escalation takes about 1~3 minutes; upon completion the current adb session directly becomes a root shell, enter id to verify uid=0(root);
  5. You can also verify with /data/local/tmp/su -c id.

Method B: Manual adb

adb push exploit /data/local/tmp/exploit
adb push ksu_loader.sh /data/local/tmp/ksu_loader.sh
adb shell chmod 755 /data/local/tmp/exploit /data/local/tmp/ksu_loader.sh

adb shell "env NO_COLOR=1 SE_LINUX=1 KSU_LOADER=1 SHELL_ROOT=1 SU_DAEMON=1 SUSPECT_CPU=99999 KS_MAX_TRIES=8 /data/local/tmp/exploit"

Verify after running:

adb shell /data/local/tmp/su -c id
# uid=0(root) gid=0(root) ...

4. Environment Variables

VariableDefaultMeaning
NO_COLOR0Disable colored logging
SE_LINUX0Enable SELinux Permissive flip (kernel anchor directly writes enforce)
KSU_LOADER0Execute ksu_loader.sh within the root anchor (KernelSU late-load)
SHELL_ROOT0Fork root shell within the anchor
SU_DAEMON0Start /data/local/tmp/su daemon within the anchor
SUSPECT_CPU-Specify suspect CPU (anchor binding), 99999 means automatic
KS_MAX_TRIES-KernelSnitch mm collision/anchor attempt limit

5. Notes

  • Network disconnection handling: when KSU flips back to Enforcing causing network disconnection, the chuxin_permissive_netfix module's service.sh automatically resets properties and restarts netd (also effective after flashing modules like LSPosed);
  • Root is temporary: it becomes invalid after reboot and requires re-running privilege escalation; SELinux permissive is automatically restored by the KSU module after boot;
  • This solution does not require unlocking the Bootloader, nor does it require flashing.

6. Disclaimer

The contents of this repository are for security research and personal device testing only. Privilege escalation/modifying system state carries certain risks; improper operation may brick the device or cause data loss. Please use it only after fully understanding the principles and accepting the consequences yourself, and do not use it for illegal purposes.


Reference: CVE-2026-43499 (GhostLock) — Linux kernel futex priority inheritance UAF, affecting kernels 2.6.39 ~ 7.1, allowing local privilege escalation.

Download Tool