Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pixel-ksu-root — CVE research and exploits to help gaining roots for Pixel devices | Kitploit
Tools/GitHubGitHub/jingmatrix/pixel-ksu-root
Android SecurityPrivilege EscalationExploit FrameworksExploitationPost-ExploitationPenetration TestingMobile SecurityRed TeamingPayload Development
GitHubjingmatrix/pixel-ksu-root

pixel-ksu-root

CVE research and exploits to help gaining roots for Pixel devices

439846 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

pixel-ksu-root

Root a stock, locked-bootloader Google Pixel from an unprivileged adb shell, using a kernel CVE — no unlock, no flash, no vendor help.

A userspace-reachable kernel bug yields a short-lived read/write primitive. That primitive is spent late-loading a KernelSU module into the running GKI kernel, after which root is handed to whichever KernelSU manager is already installed. No partition is written, so a reboot is the uninstall. Everything runs from the host over adb through a single executable, ./pixel-ksu-root.

Status

CVEthe bugwhere it stands
CVE-2026-43499 — GhostLocka futex PI walk follows an rt_mutex_waiter that remove_waiter() left dangling, read out of a stack slot pselect(2) has re-occupiedroots, hardware-verified; the default recipe, so a bare run takes it
CVE-2026-43049 — FFWheelhidpp_probe() publishes the input device before force-feedback init and returns the error without hid_hw_stop(), so a freed struct uhid_device stays reachable through /dev/input/eventNroots, hardware-verified; a use-after-free from an unprivileged shell to arbitrary kernel read/write, then an own-cred overwrite in place
CVE-2026-93189 — Joyridehid_hw_stop() never waits for input to stop, so a failed probe frees the struct hidraw that hidraw_report_event() is still writing into on another processorcandidate successor; the path to the free is walked on hardware from an unprivileged shell through /dev/uhid, and is open on builds that close both chains above
CVE-2026-46242 — BadEpoll__ep_remove() clears file->f_ep and keeps using the file, so a concurrent __fput() frees the eventpoll it is still writing throughpartial; read and write chains both run end to end, but delivery across the slab boundary is unsolved
CVE-2026-56945 — RogueWavebigo_iommu_fault_handler() walks a driver-global instance list unlocked, on a documented and incorrect assumption about its callerreachable without privilege through the public AMediaCodec API; the fault handler itself has not been entered
CVE-2026-56914 — DirtyDockgcip_iommu_mapping_unmap_buffer() dirties a pinned DMA page with the unlocked set_page_dirty() instead of its locking variant, racing teardown of the backing memorytriggerable end to end, though the device node is privilege-gated; two racing strategies disproven, timing not yet won
CVE-2026-64468 — Frostbindbinder_free_transaction() dereferences t->to_proc without holding a referencehunt; the vulnerable read runs, but the race is lost on bare metal
CVE-2026-64469 — Frostwalka sibling of Frostbind, in the same function: binder_free_transaction()'s unlocked read races binder_thread_release() walking a different thread's transaction_stackhunt; free and walk both confirmed reachable, with no root dependency in the mechanism — reaches an app process the way Shizuku does; a reclaim attempt without a verify-read (flood + pin) has yet to land — the write's actual target is still not distinguished
CVE-2026-64560 — Zombieticka process-wide POSIX CPU timer is freed while still queued, because posix_cpu_timer_del() returns early once de_thread() has nulled ->sighandhunt; the KASLR stage lands, the bridge descriptor never validates
CVE-2026-49881 — TelecomTelecom trusts a caller-supplied component name and loads it with CONTEXT_INCLUDE_CODE, so a bait app runs arbitrary Java inside system_serverresearch; a userspace domain pivot rather than a kernel bug, paired with domainprobe/
P0 465827985 — StackJumpnative code built without stack-clash protection lets a large frame step over a system_server thread's guard pagethe overflow reproduces and crashes a binder thread reliably; the reporter's spray-based write does not, so the realised primitive is a read of the crash tombstone — a full ASLR defeat for that process
Download Tool