Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/wheregoes/byd-dolphin-hacking
Android SecurityEmbedded Systems SecurityPrivilege EscalationIoT SecurityVulnerability AnalysisReverse EngineeringInformation GatheringHardware HackingBinary AnalysisPapers & Research
GitHub
591082 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
wheregoes/byd-dolphin-hacking

byd-dolphin-hacking

Reverse engineering the BYD Dolphin head unit — CAN bus, AVAS, NFC keys, OTA, and more. DiLink 3 / Android 10.

View Repository

🚗 BYD Dolphin Head Unit — Research & Reverse Engineering

Reverse engineering, documentation, and tooling for the BYD Dolphin 25/26 infotainment system (DiLink 3, Android 10).

Everything here was discovered through ADB exploration, APK decompilation, and CAN bus probing — no proprietary documentation was used.

⚠️ Disclaimer: Unofficial, community-driven project — no affiliation with BYD. Reverse engineering of BYD's internal Android services for educational and interoperability purposes only. Use at your own risk — modifying vehicle software may void your warranty or violate BYD's terms of service. The authors assume no liability for any damage to your vehicle, software, or data.


📋 Table of Contents

  • Head Unit Specs
  • Getting Started
  • Key Findings
  • Security Findings
  • Architecture
  • Documentation
  • Scripts
  • Repository Structure
  • Firmware Resources & References
  • License

🖥️ Head Unit Specs

PropertyValue
PlatformDiLink 3.0
Android10 (API 29)
SoCQualcomm QCM6125 (SM6125 Trinket)
ArchitectureARM64, 8 cores
RAM~3.5 GB
Kernel4.14.117-perf
ADBWiFi, port 5555
Head Unit IP192.168.10.10 (car WiFi)
Firmware13.1.32.2507250.1 (Jul 25 2025)
MCU13.5.2.2312260.1
DSP13.5.5.2505300.2
BootloaderUnlocked (ro.boot.flash.locked=0)
Verified bootOrange (unlocked)
Instrument ClusterSeparate Qt/QML system (Qt 5.15.10 / 6.5.5)

Tested on firmware 13.1.32.2507250.1. Older versions likely work. Newer firmware updates from BYD may change or break things — no guarantees.


🚀 Getting Started

New here? Start with the Sideloading Guide to install apps on your BYD — no root needed.

For custom apps built on this research, see byd-apps.

Quick ADB Connection

adb connect 192.168.10.10:5555

Sideloading Quick Facts

  • USB method — drop APKs in Third Party Apps XX folder (country code suffix), plug into car
  • Master password — BYD6125F (universal across DiLink 3)
  • APK requirements — ARM64, targetSdk ≤ 33, minSdk ≤ 29
  • Country-specific restrictions — Kazakhstan (14-app whitelist), India (Mappls only), Europe/Japan/Australia (online verification)

CAN Bus Injection (VCDS-Style Coding)

Inject CAN frames from ADB — no root, no OBD2 dongle:

# 1. Start the ClusterDebug app + service (acts as privileged proxy)
adb shell "am start -n com.byd.clusterdebug/.MainActivity"
adb shell "am startservice -n com.byd.clusterdebug/.ClusterDebugService"

# 2. Inject CAN frames
adb shell "am broadcast -a com.byd.cluster.spi --es normal 'FF,FF,FF,FF,FF,FF,FF,FF'"

# 3. Capture cluster screenshot
adb shell "fission_screencap -d 1 -p /data/local/tmp/cluster.png"
adb pull /data/local/tmp/cluster.png

See Driver Display for the full UDS diagnostic protocol, CAN frame format, and ECU network topology.


🔬 Key Findings

✅ What Works (No Root)

FeatureDetails
AC temperature readinggetTemprature(zone) — zone 1/2 = set temp, zone 4 = outside/ambient
Full AC control40+ getter + SET methods (start/stop, temp, fan, wind mode) via permission bypass
AC remote controlhasFeature("ACRemoteControl") = 1, supports 10–30min timer
Permission bypassBydPermissionContext (ContextWrapper) auto-grants BYDAUTO_* permissions client-side
CAN bus read/writeVia ADB using app_process + reflection
75+ BYD packagesWith CAN bus access, 100+ custom BYDAUTO_* permissions
Engine simulator soundSimulator present and switchable (HAS_SIMULATOR=2), preset selected via 0x3E300038. The MCU stores and echoes back any source type — verified to 200; only 0 is rejected — so acceptance does not imply a distinct sound and the number of real presets is not discoverable through this API. 0x48F00013 returns 1 meaning "a source exists", not a count. — Engine Sound app
AVAS preset selectionCAN-writable — UI shows 2 but MCU accepts 0–5+
setBuffer PCM streaming128-byte PCM frames accepted by MCU (ret=0) for 8+ feature IDs. Max buffer: 128 bytes. Whether MCU interprets as audio unconfirmed.
AVAH test tonesPlay on AVAS external speaker using factory diagnostic signals (0x6E970010)
AVAS melody patterns8 working patterns (doorbell, shop chime, alarm, fanfare, etc.) via TEST_AUDIO_AVAS_SET pitch control — Door Sound app
CAN bus injectionVCDS-style feature coding possible — inject CAN frames via com.byd.cluster.spi broadcast, no root needed
Cluster screenshotCapture driver display via fission_screencap -d 1 -p <file>
Instrument cluster readsPowerUnit, TempUnit, BacklightCtlType, InsThemeValue via BYDAutoManager
DRL togglesetInt(1004, 0x43100046, 1/2) — DRL auto mode ON/OFF, confirmed by readback
YUN device (1034)ALL 0xAA feature IDs accepted by MCU — setBuffer(1034, fid, data) and setInt(1034, fid, val) return 0 (OK). Cloudmanager's private MCU channel. Needs AES encryption for actuation.
Content providersExpose vehicle data (battery, tyre pressure, maintenance, trip consumption)
SideloadingUSB drive or ADB — see guide
360 camera framesLive 1280×960 from all four surround cameras, no root. bmmcamera.jar is world-readable — load it yourself and drive JNIBMMCamera directly from a shell-uid app_process. An installed app can never do this (SELinux denies untrusted_app_* the bmmcameraserver binder); a process launched over ADB can — details

⚠️ Partially Working

FeatureStatus
Door lock statusMain doors return INVALID (0), child lock readable. No dedicated setDoorLockStatus() — needs generic set() with unknown feature IDs
360 camera display controlBYDAutoPanoramaDevice (mode, rotation, transparency) is enforced server-side and the BydPermissionContext bypass fails. Frame capture works — see above

❌ What Doesn't Work

Download Tool