
Device-bound CVE-2026-64560 adaptation for RedMi K80pro miro OS 3.0.304.0
CVE-2026-64560 userspace local privilege escalation port for Redmi K80 Pro (miro).
🚀 Don't want to read all this documentation?
If you don't want to dig deep, or don't want to read this pile of AI-generated
.mdfiles, go straight todyc.md— a plain-language quick start: from zero to jailbreak (including KernelSU), covering only what commands to type, not why.
The upstream exploit and Xiaomi 15 (dada) adaptation come from
quyicheng03-boop,
and this repository is the result of porting it to K80 Pro by re-deriving addresses and constants on that basis.
This project only does porting; it does not include vulnerability discovery. The vulnerability principle and exploit chain design all belong to the upstream author. See
docs/UPSTREAM.mdandNOTICEfor details.
The source code and binaries in this repository are only valid for the single firmware version below:
| Item | Value |
|---|---|
| Device | Redmi K80 Pro (ro.product.device = miro) |
| Fingerprint | Redmi/miro/miro:16/BP2A.250605.031.A3/OS3.0.304.0.WOMCNXM:user/release-keys |
| Kernel | 6.6.118-android15-8-gc44b714366cc-abogki519650608-4k |
| Kernel build time | Thu Jun 4 03:48:35 UTC 2026 |
| Page size | 4096 (4K) |
Switching to any other OTA version will make it fail. The struct offsets, symbol addresses, and KASLR ranges
in the kernel are all derived for this one Image; being off by a single character means it won't run.
When the fingerprint doesn't match, the program exits at the gate:
TARGET_PROFILE_GATE_FAIL fingerprint=...
This is a safe failure and won't touch the kernel. If your firmware is not the version in the table above, please re-port it yourself according to
docs/05-technical.md, and do not directly
apply the constants from this repository.
docs/04-troubleshooting.md),
but do not run it on a device you do not own or whose data has not been backed up.fastboot channel in the locked state.k80pro-miro-cve-2026-64560/
├── README.md This file
├── dyc.md Quick start (plain-language version), beginners read this first
├── LICENSE Upstream license
├── NOTICE Upstream attribution notice
├── SHA256SUMS.txt Checksums of the three artifacts in release_build/
│
├── src/ Source code for compilation
│ ├── exploit-fanout-miro.c
│ ├── exploit-rotate-miro.c
│ ├── temp-su.c
│ ├── miro-profile.h Constant reference (not involved in compilation)
│ ├── miro-integration.c Integration reference (not involved in compilation)
│ └── exploit-*.c Upstream original files (generator input, not involved in compilation)
│
├── release_build/ Precompiled artifacts (ready to use)
│ ├── cve-2026-64560-fanout
│ ├── cve-2026-64560-rotate
│ └── su
│
├── docs/
│ ├── 01-build.md How to compile
│ ├── 02-usage.md How to use in adb shell
│ ├── 03-tokens.md Output token quick reference
│ ├── 04-troubleshooting.md Troubleshooting and risk explanation
│ ├── 05-technical.md Porting technical notes
│ └── UPSTREAM.md Upstream source
│
└── tools/ Build scripts and reproduction/diagnostic tools (not involved in exploitation)
├── build.sh One-click compile (sh tools/build.sh)
└── *.py Reproduction / diagnostic scripts
See docs/02-usage.md.
First confirm the artifacts are intact:
sha256sum -c SHA256SUMS.txt # Linux / macOS
certutil -hashfile <file> SHA256 # Windows, verify one by one
See docs/01-build.md.
Requires the Android NDK (you cannot use the system gcc; see that document for the reason). The easiest way is
to use the script included in the repository, which finds the NDK itself, selects the correct toolchain, compiles, and
compares hashes one by one against SHA256SUMS.txt:
sh tools/build.sh # compile + verify
sh tools/build.sh --no-check # compile only
The script only compiles; it does not touch the device, does not push, and does not run the exploit.
If you don't want to use the script, you can also manually type the three clang commands to produce
cve-2026-64560-fanout, cve-2026-64560-rotate, and su.
After compilation, compare whether it is byte-identical to what's in release_build/:
sha256sum build/* # compare against the three values in SHA256SUMS.txt
The only criterion for success is opening a new adb shell and being able to get uid=0 through /data/local/tmp/su:
$ printf 'id\nexit\n' | adb shell -T /data/local/tmp/su
uid=0(root) gid=0(root) groups=0(root),1004(input),... context=u:r:shell:s0
Note context=u:r:shell:s0 — root identity but retaining the shell domain, this is by design,
not an error.
The key tokens you will see during the process (full table in docs/03-tokens.md):
BOOTID_WRITE_PASS attempt=5 q0=... q1=... slide=... kernel_base=...
STAGE0_GATE_PASS slide=... kernel_base=...
MISC_BRIDGE_OPEN_PASS fd=... observed=...
STAGE8_CRED_STAGE_PASS task=... cred=... uid=0 context=shell
ROOT_CHILD_HOLD_PASS child=... uid=0 context=shell selinux_permissive=1
The success rate is not 100%. In the Stage0 phase, the measured single-attempt hit rate is about 1/5, so the program retries 32 times per stage by default. The entire chain is probabilistic.
Failure may manifest as a crash. A long press of the power button is required to force restart. After restart, the kernel state is completely cleared and you can try again.
After success, two states remain until reboot:
/data/local/tmp/su becomes a daemon that grants root to any shell identitySee the end of docs/02-usage.md for how to clean up.
permissive is not a leftover bug, but a prerequisite for loading kernel modules (KernelSU LKM, etc.). See
docs/04-troubleshooting.mdfor details.