
CVE research and exploits to help gaining roots for Pixel devices
Root a stock, locked-bootloader Google Pixel from an unprivileged adb shell, using a
kernel CVE — no unlock, no flash, no vendor help.
A userspace-reachable kernel bug yields a short-lived read/write primitive. That primitive
is spent late-loading a KernelSU module into the running
GKI
kernel, after which root is handed to whichever KernelSU manager is already installed.
No partition is written, so a reboot is the uninstall. Everything runs from the host over
adb through a single executable, ./pixel-ksu-root.
| CVE | the bug | where it stands |
|---|---|---|
| CVE-2026-43499 — GhostLock | a futex PI walk follows an rt_mutex_waiter that remove_waiter() left dangling, read out of a stack slot pselect(2) has re-occupied | roots, hardware-verified; the default recipe, so a bare run takes it |
| CVE-2026-43049 — FFWheel | hidpp_probe() publishes the input device before force-feedback init and returns the error without hid_hw_stop(), so a freed struct uhid_device stays reachable through /dev/input/eventN | roots, hardware-verified; a use-after-free from an unprivileged shell to arbitrary kernel read/write, then an own-cred overwrite in place |
| CVE-2026-93189 — Joyride | hid_hw_stop() never waits for input to stop, so a failed probe frees the struct hidraw that hidraw_report_event() is still writing into on another processor | candidate successor; the path to the free is walked on hardware from an unprivileged shell through /dev/uhid, and is open on builds that close both chains above |
| CVE-2026-46242 — BadEpoll | __ep_remove() clears file->f_ep and keeps using the file, so a concurrent __fput() frees the eventpoll it is still writing through | partial; read and write chains both run end to end, but delivery across the slab boundary is unsolved |
| CVE-2026-56945 — RogueWave | bigo_iommu_fault_handler() walks a driver-global instance list unlocked, on a documented and incorrect assumption about its caller | reachable without privilege through the public AMediaCodec API; the fault handler itself has not been entered |
| CVE-2026-56914 — DirtyDock | gcip_iommu_mapping_unmap_buffer() dirties a pinned DMA page with the unlocked set_page_dirty() instead of its locking variant, racing teardown of the backing memory | triggerable end to end, though the device node is privilege-gated; two racing strategies disproven, timing not yet won |
| CVE-2026-64468 — Frostbind | binder_free_transaction() dereferences t->to_proc without holding a reference | hunt; the vulnerable read runs, but the race is lost on bare metal |
| CVE-2026-64469 — Frostwalk | a sibling of Frostbind, in the same function: binder_free_transaction()'s unlocked read races binder_thread_release() walking a different thread's transaction_stack | hunt; free and walk both confirmed reachable, with no root dependency in the mechanism — reaches an app process the way Shizuku does; a reclaim attempt without a verify-read (flood + pin) has yet to land — the write's actual target is still not distinguished |
| CVE-2026-64560 — Zombietick | a process-wide POSIX CPU timer is freed while still queued, because posix_cpu_timer_del() returns early once de_thread() has nulled ->sighand | hunt; the KASLR stage lands, the bridge descriptor never validates |
| CVE-2026-49881 — Telecom | Telecom trusts a caller-supplied component name and loads it with CONTEXT_INCLUDE_CODE, so a bait app runs arbitrary Java inside system_server | research; a userspace domain pivot rather than a kernel bug, paired with domainprobe/ |
| P0 465827985 — StackJump | native code built without stack-clash protection lets a large frame step over a system_server thread's guard page | the overflow reproduces and crashes a binder thread reliably; the reporter's spray-based write does not, so the realised primitive is a read of the crash tombstone — a full ASLR defeat for that process |