Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/rmdycz/k80pro-miro-cve-2026-64560
Android SecurityPrivilege EscalationExploitationMobile App PentestingReverse EngineeringPost-ExploitationMobile SecurityPapers & ResearchPayload DevelopmentBinary Exploitation
GitHubrmdycz/k80pro-miro-cve-2026-64560

K80Pro-miro-CVE-2026-64560

Device-bound CVE-2026-64560 adaptation for RedMi K80pro miro OS 3.0.304.0

View Repository
13118 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

k80pro-miro-cve-2026-64560

CVE-2026-64560 userspace local privilege escalation port for Redmi K80 Pro (miro).

🚀 Don't want to read all this documentation?

If you don't want to dig deep, or don't want to read this pile of AI-generated .md files, go straight to dyc.md — a plain-language quick start: from zero to jailbreak (including KernelSU), covering only what commands to type, not why.

The upstream exploit and Xiaomi 15 (dada) adaptation come from quyicheng03-boop, and this repository is the result of porting it to K80 Pro by re-deriving addresses and constants on that basis.

This project only does porting; it does not include vulnerability discovery. The vulnerability principle and exploit chain design all belong to the upstream author. See docs/UPSTREAM.md and NOTICE for details.


1. Read this first: artifacts are strictly bound to firmware

The source code and binaries in this repository are only valid for the single firmware version below:

ItemValue
DeviceRedmi K80 Pro (ro.product.device = miro)
FingerprintRedmi/miro/miro:16/BP2A.250605.031.A3/OS3.0.304.0.WOMCNXM:user/release-keys
Kernel6.6.118-android15-8-gc44b714366cc-abogki519650608-4k
Kernel build timeThu Jun 4 03:48:35 UTC 2026
Page size4096 (4K)

Switching to any other OTA version will make it fail. The struct offsets, symbol addresses, and KASLR ranges in the kernel are all derived for this one Image; being off by a single character means it won't run.

When the fingerprint doesn't match, the program exits at the gate:

TARGET_PROFILE_GATE_FAIL fingerprint=...

This is a safe failure and won't touch the kernel. If your firmware is not the version in the table above, please re-port it yourself according to docs/05-technical.md, and do not directly apply the constants from this repository.


2. Disclaimer

  • This code directly reads and writes kernel memory.
  • During exploitation, the device may crash or hang, requiring a long press of the power button to force restart.
  • Failure will not cause permanent damage (see the risk analysis in docs/04-troubleshooting.md), but do not run it on a device you do not own or whose data has not been backed up.
  • The test device is in BL-unlocked state. If your device's bootloader is locked, first confirm you have a recovery method — there is no fastboot channel in the locked state.
  • For security research, vulnerability verification, and learning on your own device only. Please confirm the legal requirements of your region yourself.

3. Directory structure

k80pro-miro-cve-2026-64560/
├── README.md               This file
├── dyc.md                  Quick start (plain-language version), beginners read this first
├── LICENSE                 Upstream license
├── NOTICE                  Upstream attribution notice
├── SHA256SUMS.txt          Checksums of the three artifacts in release_build/
│
├── src/                    Source code for compilation
│   ├── exploit-fanout-miro.c
│   ├── exploit-rotate-miro.c
│   ├── temp-su.c
│   ├── miro-profile.h      Constant reference (not involved in compilation)
│   ├── miro-integration.c  Integration reference (not involved in compilation)
│   └── exploit-*.c         Upstream original files (generator input, not involved in compilation)
│
├── release_build/          Precompiled artifacts (ready to use)
│   ├── cve-2026-64560-fanout
│   ├── cve-2026-64560-rotate
│   └── su
│
├── docs/
│   ├── 01-build.md         How to compile
│   ├── 02-usage.md         How to use in adb shell
│   ├── 03-tokens.md        Output token quick reference
│   ├── 04-troubleshooting.md  Troubleshooting and risk explanation
│   ├── 05-technical.md     Porting technical notes
│   └── UPSTREAM.md         Upstream source
│
└── tools/                  Build scripts and reproduction/diagnostic tools (not involved in exploitation)
    ├── build.sh            One-click compile (sh tools/build.sh)
    └── *.py                Reproduction / diagnostic scripts

4. Two usage paths

Path A: Use the precompiled artifacts directly

See docs/02-usage.md.

First confirm the artifacts are intact:

sha256sum -c SHA256SUMS.txt        # Linux / macOS
certutil -hashfile <file> SHA256   # Windows, verify one by one

Path B: Compile it yourself

See docs/01-build.md.

Requires the Android NDK (you cannot use the system gcc; see that document for the reason). The easiest way is to use the script included in the repository, which finds the NDK itself, selects the correct toolchain, compiles, and compares hashes one by one against SHA256SUMS.txt:

sh tools/build.sh              # compile + verify
sh tools/build.sh --no-check   # compile only

The script only compiles; it does not touch the device, does not push, and does not run the exploit.

If you don't want to use the script, you can also manually type the three clang commands to produce cve-2026-64560-fanout, cve-2026-64560-rotate, and su.

After compilation, compare whether it is byte-identical to what's in release_build/:

sha256sum build/*              # compare against the three values in SHA256SUMS.txt

5. What success looks like

The only criterion for success is opening a new adb shell and being able to get uid=0 through /data/local/tmp/su:

$ printf 'id\nexit\n' | adb shell -T /data/local/tmp/su
uid=0(root) gid=0(root) groups=0(root),1004(input),... context=u:r:shell:s0

Note context=u:r:shell:s0 — root identity but retaining the shell domain, this is by design, not an error.

The key tokens you will see during the process (full table in docs/03-tokens.md):

BOOTID_WRITE_PASS attempt=5 q0=... q1=... slide=... kernel_base=...
STAGE0_GATE_PASS  slide=... kernel_base=...
MISC_BRIDGE_OPEN_PASS fd=... observed=...
STAGE8_CRED_STAGE_PASS task=... cred=... uid=0 context=shell
ROOT_CHILD_HOLD_PASS child=... uid=0 context=shell selinux_permissive=1

6. Three behavioral characteristics you must know

  1. The success rate is not 100%. In the Stage0 phase, the measured single-attempt hit rate is about 1/5, so the program retries 32 times per stage by default. The entire chain is probabilistic.

  2. Failure may manifest as a crash. A long press of the power button is required to force restart. After restart, the kernel state is completely cleared and you can try again.

  3. After success, two states remain until reboot:

    • SELinux becomes permissive
    • /data/local/tmp/su becomes a daemon that grants root to any shell identity

    See the end of docs/02-usage.md for how to clean up.

permissive is not a leftover bug, but a prerequisite for loading kernel modules (KernelSU LKM, etc.). See docs/04-troubleshooting.md for details.


7. Acknowledgments

Download Tool