
GhostLock (CVE-2026-43499) app for the Galaxy S26 series
indev.ghostlock.s26)One-click Android wrapper for polygraphene/ghostlock-s26: GhostLock (CVE-2026-43499) ported to the whole Samsung Galaxy S26 series (Android 16 / GKI 6.12). One APK, three kernel lines, runtime parameter matching - no per-build app variants.
Use only on devices you own or are explicitly authorized to test. Temp root vanishes on reboot. A second exploit run in the same boot can crash the device - reboot before retrying.
Disclaimer: experimenting with this software involves low-level kernel exploits, root, and boot-time claims. It is provided AS IS, without warranty of any kind. You use it entirely at your own risk; the author is not responsible for bricked, boot-looped, or otherwise damaged devices, or for any data loss, voided warranties, or damage arising from its use.
The exploit matches by kernel line, not by individual build
(exploit/src/params_table.c is authoritative; ParamsTable.kt mirrors it
for the UI verdict only):
| Device codename | Marketing | SoC | Kernel line |
|---|---|---|---|
| m1q | Galaxy S26 (SM-S942x) | Snapdragon | cn or intl (by CSC) |
| m2q | Galaxy S26+ (SM-S947x) | Snapdragon | cn or intl (by CSC) |
| m3q | Galaxy S26 Ultra (SM-S948x) | Snapdragon | cn or intl (by CSC) |
| m1s | Galaxy S26 (SM-S942B) | Exynos | exynos |
| m2s | Galaxy S26+ (SM-S947B) | Exynos | exynos |
Tested builds (17): S9420ZCS4AZG1, S9470ZCS4AZG1, S9480ZCS3AZF1, S9480ZCS4AZG1, S942BXXS4AZG5, S947BXXS3AZF1, S947BXXS4AZG5, S942QOPU1AZDE, S942U1UES4AZG3, S942USQS4AZG3, S947USQS4AZG3, S9480ZHS4AZG1, S948BXXS4AZG5/6, S948NKSS4AZG3, S948U1UES2AZE1, S948USQS4AZG3.
Unknown OTAs fall back exactly like upstream params.c: exact build first,
then same model + 3-char CSC (OTA reuse), then latest same-device entry
(flagged unverified), else fail-closed (the app shows UNSUPPORTED and the
native layer exits 2). Completely unknown models are refused - never forced.
One big button - Root my S26 - runs the whole pipeline and narrates into the Output card:
adb shell flow). Permission is requested
once at launch (and again if the server restarts); the Root flow waits for
the grant instead of bailing. If the server is down the app opens the
Shizuku manager so you can start it, then falls back to the in-app shell.
Adding the app to Shizuku's allowlist removes the prompt entirely.preload.so, su_daemon, ksud to /data/local/tmp
(preload.so, cve-2026-43499-root, ksud) and chmods them. If you
already adb pushed the files per the upstream README, they are picked up
in place.env LD_PRELOAD=/data/local/tmp/preload.so sh (the .so constructor runs
the chain and _exits; stdout is the exploit log), up to 5 attempts -
the race is probabilistic. A BOOT_FORCE=1 switch is available but
rebooting is safer.id reports uid=0 through any channel:
temp-daemon socket first, then KernelSU-style su. This matters because on
a full success su_daemon unlinks its socket and exits by design
(handover to KernelSU) - a dead temp socket with working su means
rooted, not broken. Prints the boot-claim log tail and reports rooted /
exit-code advice.Below that: a single command field + Run as root row (one-shot commands
via the su daemon's C protocol; interactive PTY is out of scope for v1),
and a small Reset link that clears /data/local/tmp/ghostlock-boot.log
so a run can be retried without rebooting (upstream warns this may panic -
reboot is the safe path).
exploit/ vendored upstream (Makefile + src/, authoritative)
ksud upstream prebuilt KernelSU loader (ARM64 PIE, also in assets)
app/src/main/assets/ksud staged copy shipped in the APK
app/src/main/assets/ + preload.so / su_daemon after stage-assets.sh
app/src/main/cpp/ optional CMake rebuild of preload.so from exploit/src
app/src/main/java/indev/ghostlock/s26/
MainActivity.kt UI (device / stage / run / shell / boot guard)
ParamsTable.kt series table mirror (17 builds, 3 lines, 5 codenames)
DeviceCompat.kt Build.* identity + series verdict
ShellRunner.kt Shizuku (uid 2000) + local fallback, staging
SuClient.kt /data/local/tmp/temp_su.sock 'C'-mode client
GhostlockManager.kt exit-code interpreter (0/1/2/3/4)
PORTING.upstream.md porting notes (new firmware = new device_map row)
Requirements: Android Studio (JBR 21) / SDK 35 / NDK r26+ / CMake 3.22.1 / JDK 17.
# 1. Build the native payloads with the NDK (upstream flow):
cd exploit && make preload
# -> build/bin/preload.so, build/embed/su_daemon_aarch64_pie
# 2. Stage them into the APK assets:
./stage-assets.sh
# 3. Build the app:
./gradlew :app:assembleDebug
# -> app/build/outputs/apk/debug/app-debug.apk
ksud is already vendored (ksud + app/src/main/assets/ksud) so step 1–2
only produce the two NDK outputs. The CMake target in
app/src/main/cpp/CMakeLists.txt can additionally rebuild libpreload.so
from the same sources inside the APK as a fallback.
The .github/workflows/build.yml workflow
builds the app tailored to the target device codename / processor type - no
SDK, NDK, or Docker needed locally. Fork the repo, then from the repo's Actions tab →
GhostLock-S26 Device Build → Run workflow, then set:
| Input | Choice | Default | Effect |
|---|---|---|---|
device | all / m1q / m2q / m3q / m1s / m2s | all | Device codename (build target) |
processor | all / snapdragon / exynos | all | SoC family (filters kernel lines) |
kernel_line | auto / cn / intl / exynos | auto | Pin the exact params line (auto derives from device/processor) |
tailor | on / off | off | Prune params_table.c + ParamsTable.kt to the selected device/line for a smaller single-target payload |
build_type | debug / release | debug | APK variant |
rebuild_ksud | on / off | on | Rebuild ksud + kernelsu.ko from polygraphene/KernelSU at ksud_ref, or keep the vendored prebuilt |
kmi | android16-6.12 / android15-6.6 | android16-6.12 | KMI the module is compiled for (S26 = GKI 6.12) |
samsung_hardening | on / off | on | CONFIG_KSU_SAMSUNG_KDP/RKP/DEFEX=y (Samsung kdp creds, RKP/DEFEX sync) |
no_patch_text | on / off | off | Disable live text patching (Samsung Exynos EL2 targets) |
Plus ksud_ref, ddk_release and ksu_manager_apk for pinning the KernelSU
source ref / DDK image / bundled Manager APK, and sign_release to sign with
the KEYSTORE_BASE64 / KEY_ALIAS / secrets.
For example, a Snapdragon-only Galaxy S26 Ultra build (kernel lines cn +
intl, with the other devices pruned out) would be: device=m3q,
processor=snapdragon, tailor=on.