Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
opace6-cve-2026-64560 — OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address | Kitploit
Tools/GitHubGitHub/qingle009/opace6-cve-2026-64560
Android SecurityPrivilege EscalationVulnerability AnalysisExploitationMobile App PentestingPost-ExploitationMobile SecurityPapers & ResearchPayload DevelopmentBinary Exploitation
GitHub
1 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
qingle009/opace6-cve-2026-64560

opace6-cve-2026-64560

OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address

View Repository

OnePlus Ace 6 临时 Root 工具

通过 CVE-2026-64560(Linux 内核 POSIX CPU timer UAF)漏洞获取 OnePlus Ace 6 当前启动周期的临时 root 权限。重启后失效,不修改系统分区。

[!WARNING] 可能导致设备重启或数据丢失。仅在你自己的设备上使用,操作前请备份重要数据。

支持的设备

项目信息
设备OnePlus Ace 6 (OP6113L1)
固件指纹OnePlus/PLQ110/OP6113L1:16/BP2A.250605.015/...
内核版本6.6.118-android15-8-...

如果你的系统版本指纹不匹配,工具会拒绝运行并提示 TARGET_PROFILE_GATE_FAIL。

使用前准备

  1. 一台 OnePlus Ace 6,系统版本与上面匹配
  2. 一台电脑(Windows / macOS / Linux 均可)
  3. USB 数据线
  4. 手机已开启 USB 调试(设置 → 关于手机 → 连点版本号 7 次开启开发者选项 → 开发者选项 → USB 调试)
  5. 电脑已安装 adb(下载地址,解压后把路径加到系统 PATH)

步骤 1 — 下载工具

前往本仓库的 Releases 页面,下载最新版的 cve-2026-64560-fanout-opace6。

把下载的文件放到一个你记得住的位置,比如桌面。

步骤 2 — 连接设备

用 USB 线连接手机和电脑,手机上弹窗点「允许 USB 调试」。

打开终端(Windows 按 Win+R 输入 cmd 回车),验证设备已连接:

root@kitploit:~
adb devices

应该能看到你的设备序列号,状态为 device。如果显示 unauthorized,请在手机上点允许。

步骤 3 — 推送到手机

Windows:

root@kitploit:~
adb push C:\Users\你的用户名\Desktop\cve-2026-64560-fanout-opace6 /data/local/tmp/
adb shell chmod 777 /data/local/tmp/cve-2026-64560-fanout-opace6

macOS / Linux:

root@kitploit:~
adb push ~/Desktop/cve-2026-64560-fanout-opace6 /data/local/tmp/
adb shell chmod 777 /data/local/tmp/cve-2026-64560-fanout-opace6

注意: 必须给 777 权限,755 会报 Permission denied。

步骤 4 — 预检

先运行预检确认你的设备可以使用:

root@kitploit:~
adb shell /data/local/tmp/cve-2026-64560-fanout-opace6 --preflight

看到 PREFLIGHT_PASS 说明一切正常,可以继续。 看到 TARGET_PROFILE_GATE_FAIL 说明你的系统版本不匹配,无法使用。

步骤 5 — 运行

这个工具利用的是内核竞态条件,有概率性,可能需要多次尝试甚至多次重启。

方式 A:使用自动脚本(推荐)

自动脚本会帮你重试,包括自动重启设备、等待冷却、检测成功。

Windows:

把本仓库的 scripts\boot-campaign.bat 和下载的 payload 放在同一个文件夹, 然后在 CMD 中进入该文件夹运行:

root@kitploit:~
boot-campaign.bat -n 6

-n 6 表示最多重启 6 次尝试。脚本会自动:

  • 推送文件到手机
  • 运行预检
  • 运行 exploit 并实时显示进度(attempt 次数)
  • 如果失败,重启设备降温后重试
  • 成功后自动退出

macOS / Linux:

root@kitploit:~
sh scripts/boot-campaign.sh -p cve-2026-64560-fanout-opace6 -n 6

(可选:-u cve-2026-64560-su 指定 temp-su 路径,成功后 root 会话可跨终端使用。)

方式 B:手动运行

root@kitploit:~
adb shell /data/local/tmp/cve-2026-64560-fanout-opace6 --run

如果没有成功(没有看到 ROOT_SUCCESS),重启手机再试。建议等手机摸起来不烫了再试, CPU 温度过高会降低成功率。

步骤 6 — 使用 root

成功后会看到 ROOT_SUCCESS / ROOT_CHILD_HOLD_PASS。 root shell 就在运行 --run 的那个终端窗口里(exploit 会提示 interactive root child; exit to finish),直接输入 id,看到 uid=0(root) 就说明已经获取 root 权限了。

如果想在另一个终端里使用 root,需要先让 root 会话常驻:

  1. 获取 cve-2026-64560-su(不在 Release 中,见仓库 Actions 构建产物, 或用 Android NDK 编译 src/temp-su.c),推送到手机:

    root@kitploit:~
    adb push cve-2026-64560-su /data/local/tmp/su
    adb shell chmod 755 /data/local/tmp/su
    
  2. 在 exploit 的 root shell 里执行:

    root@kitploit:~
    /data/local/tmp/su --daemon
    
  3. 之后在任意终端执行 adb shell /data/local/tmp/su,输入 id 验证。

注意: 使用 boot-campaign.bat / boot-campaign.sh 时,把 cve-2026-64560-su 和 payload 放在同一目录(或用 -u 指定路径), 脚本会自动推送并启动 daemon。

重要: root 权限只在本次开机有效,手机重启后需要重新运行。 不会修改 boot、vendor、system 分区,不影响 OTA 更新。

来源与许可

上游:NebuSec/CyberMeowfia。 具体修订和 Linux 修复见 docs/UPSTREAM.md。 Apache License 2.0;见 LICENSE 和 NOTICE。

Download Tool