Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
F9360-CVE43499 — SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko. Device-verified 2026-08-12. | Kitploit
Tools/GitHubGitHub/e-r-butch/f9360-cve43499
Android SecurityPrivilege EscalationExploitationReverse EngineeringMobile SecurityLearning & EducationFirmware AnalysisBinary Exploitation
GitHube-r-butch/f9360-cve43499

F9360-CVE43499

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko. Device-verified 2026-08-12.

43529 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

SM-F9360 (Galaxy Z Fold4 / q4q) Bootloader-Unlock-Free KernelSU Root

CVE-2026-43499 temporary root → LD_PRELOAD channel bypasses DEFEX → no-LTO clang-12 build of kernelsu.ko → full su + KernelSU Manager functionality

Status: ✅ Verified on real device 2026-08-12 (firmware F9360ZCSAIZF1, kernel 5.10.236-android12-9-2755199-abF9360ZCSAIZF1)

This project documents a complete, reproducible procedure for achieving KernelSU root on a bootloader-locked Samsung device: no BL unlock, no boot.img flashing, no Odin required.


TL;DR (English): This repo documents a fully device-verified jailbreak path for a locked-bootloader Samsung Galaxy Z Fold4 (SM-F9360, SM8450, kernel 5.10.236, firmware F9360ZCSAIZF1): a CVE-2026-43499 (rtmutex UAF, fixed in July-2026 firmware) exploit chain grants temporary kernel-domain root; a custom LD_PRELOAD constructor .so bypasses Samsung's DEFEX execve interceptor to init_module() a KernelSU LKM built with the exact device toolchain (AOSP clang 12.0.5 r416183b) and with LTO disabled — the two factors that make the module loadable and its init executable on this CFI/LTO hardened kernel. Result: su works (uid=0, context=u:r:ksu:s0) and KernelSU Manager v3.2.5 recognizes the kernel. Root is in-memory only: every reboot requires re-running the exploit (~3 min, scripted). All pitfalls and dead ends (fake exports, CRC patching, ksud late-load, LTO function-sections layout) are documented below.


Table of Contents

  • 1. Results and Fundamental Limitations
  • 2. Background: Why It's Hard, Why It's Feasible
  • 3. Attack Chain Overview (3 Layers)
  • 4. Environment Requirements
  • 5. Step 1 — Build the exploit (temporary root)
  • 6. Step 2 — Build kernelsu.ko (no-LTO clang-12 recipe)
  • 7. Step 3 — Build ksu-load.so (DEFEX bypass loader)
  • 8. Step 4 — On-device execution and verification
  • 9. Recovery Procedure After Reboot
  • 10. Key Findings and Pitfall Checklist
  • 11. Firmware/Kernel Compatibility
  • 12. Acknowledgements and Upstream Projects
  • 13. Disclaimer

1. Results and Fundamental Limitations

ItemStatus
Temporary root (kernel domain kernel:s0)✅ Achieved reliably (9 consecutive successes)
KernelSU module load (init_module)✅ kernelsu ... Live (O)
Full KSU init execution✅ All 15 instrumentation marks green
su command✅ uid=0(root) gid=0(root) context=u:r:ksu:s0
KernelSU Manager v3.2.5✅ Recognizes kernel version (supercall detection passes), works under SELinux enforcing mode
Bootloader unlock❌ Not required
Flashing/modifying partitions❌ Not required

Fundamental limitation: BL lock → root is purely in-memory. After every reboot, the exploit must be re-run and the module reloaded (full procedure ~3 minutes, scripted). The ksud userspace daemon cannot be deployed (DEFEX blocks execve, see §10-4), but su / supercall / Manager are all handled directly by the kernel sucompat, with no dependency on ksud.

Warning: rmmod kernelsu will immediately panic and reboot the device (RKP-protected syscall-table restore path) — never unload it.

2. Background: Why It's Hard, Why It's Feasible

Why it's hard (Samsung's defense in depth)

  • BL lock: OEM lock cannot be unlocked, fastboot oem unlock does not exist; any persistent root (magisk/kernel patch) requires flashing boot.img, and a locked BL rejects all self-signed images.
  • KDP / RKP / DEFEX: Kernel Data Protection (physical writes to rodata trigger a KDP monitor hard reboot), RKP hypervisor protects the syscall table, DEFEX intercepts execution of new ELFs in the root domain.
  • CFI + LTO kernel: CONFIG_CFI_CLANG=y + Full LTO. The only source of mod->init is the CFI jump-table slot __cfi_jt_init_module; indirect calls must go through a .cfi_jt table entry, otherwise the CFI check panics immediately.
  • TRIM_UNUSED_KSYMS: ~40 symbols needed by KSU are trimmed from the __ksymtab export table, so a normal insmod cannot resolve them (Unknown symbol).
  • MODULE_FORCE_LOAD=n + modversions: vermagic must match character-for-character; the IGNORE_MODVERSIONS/IGNORE_VERMAGIC flags all lead to the try_to_force_load() dead end.

Why it's feasible

  1. CVE-2026-43499 (rtmutex proxy-lock rollback UAF, fixed upstream in 2026-07) can reliably escalate to the kernel domain on 2026-06 and earlier firmware — the community already has a real-device-verified port for the same SoC (SM8450) + same kernel branch (5.10): sarabpal-dev/IonStack-S22U (b0q / S22U, exp32 route).
  2. DEFEX only blocks execve, not dynamic loading: an LD_PRELOAD constructor .so is the only exempt channel for executing arbitrary code in the root domain.
  3. KernelSU v3.2+'s jailbreak mode (ksud late-load) was designed precisely for BL-locked devices: no boot flashing, just runtime init_module.
  4. Toolchain matching principle: CFI type-ids are LLVM-internal hashes, so the module must be built with the exact same compiler as the device kernel (q4q device = AOSP clang 12.0.5 r416183b).
  5. LTO split layout is the ultimate root cause of module crashes: the 447 small ALLOC sections produced by function-sections always crash on the Samsung kernel loader; rebuilding with LTO disabled → traditional 22-section layout → success on the first try (see §10-1).

3. Attack Chain Overview (3 Layers)

┌─ Layer 1: CVE-2026-43499 temporary root
│   ionstack-q4q exploit (KASLR leak → mm reclaim → exp32 32-bit stack stamp
│   → CFI r/w → pipe physrw → UMH root daemon)
│   → /data/local/tmp/cve-2026-43499-root -c '<cmd>' = kernel:s0 domain root command channel
│
├─ Layer 2: LD_PRELOAD .so loading channel (DEFEX bypass)
│   DEFEX intercepts execve of any new ELF in the kernel domain (Killed); LD_PRELOAD constructor
│   execution is exempt → ksu-load.so inside the /system/bin/true process:
│   reads ko → manually relocates 201 UND symbols via /proc/kallsyms (SHN_ABS + st_value=absolute address)
│   → vermagic patch (needed for older versions) → init_module() → success
│
└─ Layer 3: KernelSU kernel module (no-LTO clang-12 build)
    Full init execution, all 15 marks green → sucompat (allow_shell=1) + supercall available

4. Environment Requirements

Device

ItemValue
ModelSM-F9360 (Galaxy Z Fold4, q4q)
SoCSM8450 (Snapdragon 8+ Gen 1)
FirmwareF9360ZCSAIZF1 (built ≤ 2026-06, contains the CVE)
Kernel5.10.236-android12-9-2755199-abF9360ZCSAIZF1
Device compilerAOSP clang 12.0.5 (r416183b, c935d99d7cf) (confirmed via /proc/version)
Exact vermagic5.10.236-android12-9-2755199-abF9360ZCSAIZF1 SMP preempt mod_unload modversions aarch64

Different firmware = different kallsyms / layout / vermagic, requiring re-adaptation of target.h and a rebuild. See §11.

Build machine

Download Tool