Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-56426 — CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F | Kitploit
Tools/GitHubGitHub/xcracker000/cve-2024-56426
Android SecurityEmbedded Systems SecurityExploitationReverse EngineeringHardware HackingMobile SecurityHardware SecurityPayload DevelopmentFirmware AnalysisBinary Exploitation
GitHub
41271 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
xcracker000/cve-2024-56426

CVE-2024-56426

CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F

View Repository

SM-G985F / Exynos9830 Bootrom exploit

[!CAUTION] The current key bundle and generated files are fusing-capable. Once a device has been fused, the eFuse change is irreversible and the device must continue to use boot images and key material that match the fused key. Using these files or flows is at your own risk because of the fusing behavior; all consequences remain the responsibility of the user running them. Verify the eFuse file, private keys, signed FWBL1, LK / sboot.bin images, and target device before running any fusing flow.

Contents

  • Repository Layout
  • Requirements
  • Image Preparation
  • Payload Build
  • Signed SBoot Image Generation
  • Exploit Modes
  • Exynos 9830 Boot Chain
  • Exynos 9830 Image Layout
  • Load Addresses
  • Boot Source IDs
  • Dump /mem Payload
  • Upstream Attribution
  • Credits

Repository Layout

PathPurpose
bootLoaderFiles/Bootloader binaries, split bootloader parts, original images, decrypted images, and dump artifacts.
bootromNotes/Boot ROM notes, flowcharts, and USB context offsets.
exploit/Python tooling, exploit runner, split/merge scripts, payload build helper, and SoC data.
exploit/extra/images/Working bootloader images consumed by the exploit flows.
exploit/extra/payloads/Built payload binaries copied from external/payloads/.
external/Payload sources, build Makefile, decompiled notes, shared key material, and helper tools.
external/keys/exynos9830_crecker/Shared Exynos9830 / Exynos990 custom-key bundle used by the signed-loader flow.
exynos990reverseEng/Exynos 990 reverse engineering project files.

Requirements

Linux Toolchain

sudo apt-get update
sudo apt-get install -y gcc-aarch64-linux-gnu binutils-aarch64-linux-gnu

macOS Toolchain

brew tap messense/macos-cross-toolchains
brew install aarch64-unknown-linux-gnu

Python Dependencies

python3 -m pip install -r requirements.txt

requirements.txt includes coloredlogs, cryptography, hexdump, libusb, pyusb, and pycryptodome.

Windows USB Driver

On Windows, the BootROM USB device 04e8:1234 must use a WinUSB/libusb-compatible driver before PyUSB can open it. See exploit/windows/README.md.

The repository includes a WinUSB driver package at exploit/windows/Exynos_USB_Device.inf, with its matching catalog and certificate import file in the same directory.

Image Preparation

Split sboot.bin

python3 exploit/split.py bootLoaderFiles/originalSboot_K/sboot.bin -o exploit/extra/images

The split script writes image parts and a split_manifest.json file into the output directory.

Patch LK Custom Key

The LK image must use the ROM secure boot key 2 command IDs for the custom-key flow:

Key 1 commandValueKey 2 commandValue
CMD_W_ROM_SEC_BOOT_KEY10x001CMD_W_ROM_SEC_BOOT_KEY20x016
CMD_W_USE_ROM_SEC_BOOT_KEY10x002CMD_W_USE_ROM_SEC_BOOT_KEY20x017
CMD_C_ROM_SEC_BOOT_KEY10x100CMD_C_ROM_SEC_BOOT_KEY20x114
CMD_R_USE_ROM_SEC_BOOT_KEY10x101CMD_R_USE_ROM_SEC_BOOT_KEY20x115

When applying the LK patch TSV inside the Ghidra project, the helper was called through Ghidra headless like this:

GHIDRA=/path/to/ghidra_12.0.4_PUBLIC
REPO=$(pwd)
"$GHIDRA/support/analyzeHeadless" "$REPO/exynos990reverseEng" exynos990 \
  -process lk.bin \
  -noanalysis \
  -scriptPath "$REPO/external/ghidra" \
  -postScript ApplyLkPatches.java "$REPO/external/ghidra/lk_985_selected_patches.tsv"

Embed the 32-byte eFuse key into lk.bin at offset 0x205008, replacing the stock key:

dd if=external/keys/exynos9830_crecker/crecker.efuse of=exploit/extra/images/lk.bin bs=1 seek=$((0x205008)) count=32 conv=notrunc
xxd -g1 -s $((0x205008)) -l 32 exploit/extra/images/lk.bin

Merge Split Parts

python3 exploit/merge.py exploit/extra/images Exynos9830

The merge script writes sboot.bin in the current working directory.

Payload Build

Build the payload projects under external/payloads/ and copy the resulting binaries into exploit/extra/payloads/:

./exploit/build_payloads.sh
PayloadOutput pathPurpose
mem.binexploit/extra/payloads/mem.binBoot ROM memory dump payload.
loader.binexploit/extra/payloads/loader.binUFS path payload used by --ufs.
Exynos990_boot_custom_key.binexploit/extra/payloads/Exynos990_boot_custom_key.binCustom-key signed-loader payload used by --signed.

The UFS loader and custom-key payload embed a 32-byte efuse file at build time. By default the Makefile reads external/keys/exynos9830_crecker/crecker.efuse; override this with CUSTOM_KEY_EFUSE=/path/to/crecker.efuse when needed.

Signed SBoot Image Generation

The preflight step run by exploit/exploit.py re-signs the SBoot image set in exploit/extra/images/ in place before each signed run. No separate signed output is kept. The signing step uses the intentionally tracked shared key bundle under external/keys/exynos9830_crecker/.

Equivalent repo-root command for the complete image set:

python3 external/tools/sign_sboot_images.py \
  --images-dir exploit/extra/images \
  --keys-dir external/keys/exynos9830_crecker

This signs:

ImageKey material usedRollback revision
fwbl1.imgBL1 private key + Stage2 TEE/REE pubkeys23
epbl.imgStage2 TEE private key23
bl2.imgStage2 REE private key23
lk.binStage2 REE private key23
el3_mon.imgStage2 TEE private key23
ldfw.imgStage2 TEE private key, inner + outer23
tzsw.imgStage2 TEE private key, inner + outer23

The batch signer passes decimal 23 for every image and does not reuse an older rollback value already present in an existing footer.

epbl.img is re-encrypted first when needed, then signed over the final bytes. ldfw.img and tzsw.img still need the external AVB flow if their AVB content is meant to be refreshed.

The FWBL1-only command is:

Download Tool