Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
cve-2026-43499-firetv-sheldonp-writeup — Security research write-up on exploiting CVE-2026-43499 on the Amazon Fire TV Stick 3rd Gen (sheldonp), from temporary root to bootloader unlock. | Kitploit
Outils/GitHubGitHub/accessmodifier364/cve-2026-43499-firetv-sheldonp-writeup
Android SecurityEmbedded Systems SecurityPrivilege EscalationVulnerability AnalysisExploitationReverse EngineeringMobile SecurityHardware & IoT Security

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Papers & Research
Learning & Education
GitHubaccessmodifier364/cve-2026-43499-firetv-sheldonp-writeup

cve-2026-43499-firetv-sheldonp-writeup

Security research write-up on exploiting CVE-2026-43499 on the Amazon Fire TV Stick 3rd Gen (sheldonp), from temporary root to bootloader unlock.

Voir le dépôt
168il y a 18 joursPas encore vérifié
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

CVE-2026-43499 on Amazon Fire TV Stick 3rd Gen (sheldonp)

Chaining a Linux kernel privilege escalation into a preloader downgrade and bootloader unlock.

License: MIT

Overview

This repository documents my authorized reproduction of the CVE-2026-43499 exploitation chain on an Amazon Fire TV Stick 3rd Gen (sheldonp). The chain used temporary kernel root to run a controlled preloader downgrade, then used the existing Kamakiri BootROM workflow to reach unlocked fastboot and complete the bootloader unlock.

This is a reproduction and device-specific case study. I did not discover CVE-2026-43499, create the original IonStack/GhostLock exploit, or develop Kamakiri. The upstream researchers and developers are credited below.

[!IMPORTANT] This write-up is a technical record, not a universal rooting guide. Build compatibility matters, temporary root is not persistent root, and mistakes involving Preloader, LK, TEE, or dm-verity-protected partitions can permanently brick the device.

Reproduction record

The end-to-end chain was completed on September 12, 2026. This repository records the tested device and software versions, the exact archives used, their SHA-256 hashes, and original evidence captured during the process.

Scope

FieldReproduction target
DeviceAmazon Fire TV Stick 3rd Gen
ModelAFTSSS
Codenamesheldonp
Operating systemFire OS 7.7.1.6 / build PS7716.5666N
Incremental0036005356164
Android baseAndroid 9
Kernel4.4.162+
Host used for BootROM stageUbuntu 26.04.1 LTS, booted as a live USB session
Android platform tools37.0.1
Temporary-root implementationR0rt1z2/GhostLock 1.1.0, 4.4 branch
BootROM implementationkamakiri-sheldon-1.0
ResultTemporary root, preloader downgrade, unlocked bootloader, TWRP, and preserved Fire OS

Out of scope: vulnerability discovery, a new exploit implementation, remote exploitation, persistent root, or support for devices other than the tested sheldonp unit. No custom ROM was installed during this reproduction.

Reproduction archives

The following are the exact ZIP archives used during this reproduction. The archives are not redistributed in this repository; their SHA-256 hashes are recorded so independently obtained copies can be compared with the files used in this case study.

ArchiveSourceVersionSHA-256
ghostlock-sheldon-v1.1.0.zipTemporary-root and downgrade guide on XDAGhostLock 1.1.08D541F7DF58487AF6D6D45D778482D3455A71F62E32651751CFE0B2DDFC6554F
kamakiri-sheldon-1.0.zipBootloader-unlock guide on XDAKamakiri Sheldon 1.01B07161D9F894935E5918A9B8F9A230F67B9487E9863C242E758338E8C6C5784

These hashes identify the copies used in this case study; readers should still compare their downloads against the original upstream sources and review the applicable third-party licenses.

Technical background

CVE-2026-43499, also known as GhostLock, is a use-after-free in the Linux kernel's priority-inheritance futex/rtmutex path. During proxy-lock rollback, remove_waiter() operated on current instead of the task stored in waiter->task. As a result, the actual waiter could return to userspace with pi_blocked_on still referencing an rt_mutex_waiter in a released kernel stack frame.

The original IonStack research turns that dangling stack reference into a local privilege-escalation primitive. R0rt1z2 adapted the technique to the Fire TV Stick 3rd Gen and Fire TV Stick Lite (sheldonp/sheldon) running Fire OS 7 on a 4.4 kernel.

The key distinction in this case study is that CVE-2026-43499 does not unlock the bootloader directly. It provides temporary kernel-level access. That short-lived access makes it possible to perform the controlled preloader downgrade required before the older Kamakiri BootROM chain can run.

Exploit chain

flowchart LR
    A[Fire OS 7 on sheldonp] --> B[CVE-2026-43499 / GhostLock]
    B --> C[Temporary root shell]
    C --> D[Controlled preloader downgrade]
    D --> E[Expected non-booting transition state]
    E --> F[Kamakiri BootROM stage]
    F --> G[Unlocked fastboot]
    G --> H[Bootloader unlocked]

The chain crosses two separate security boundaries:

  1. Kernel boundary: an unprivileged local process gains a temporary root context through GhostLock.
  2. Boot-chain boundary: temporary root prepares the device for a known BootROM-based unlock path by restoring a compatible preloader.

Methodology

1. Establish the baseline

Before changing the device, I identified the hardware codename and recorded the Fire OS, build, bootloader, and kernel versions over ADB.

adb devices -l
adb shell getprop ro.product.device
adb shell getprop ro.product.model
adb shell getprop ro.build.version.release
adb shell getprop ro.build.version.incremental
adb shell getprop ro.build.fingerprint
adb shell getprop ro.bootloader
adb shell uname -a
adb shell id

The resulting baseline was sheldonp / AFTSSS, Fire OS PS7716.5666N, incremental 0036005356164, Android 9, and kernel 4.4.162+. The serial number is deliberately omitted.

ADB shell baseline showing the unprivileged shell context

2. Obtain temporary root with GhostLock

I connected the Fire TV over USB with ADB debugging enabled and used GhostLock 1.1.0, the sheldon/sheldonp package published with the R0rt1z2 XDA guide. The device-specific launcher reboots the Fire TV to start from a fresh state, deploys the exploit, and retries when necessary.

Successful exploitation creates a temporary root environment. I verified the security context from an ADB shell rather than treating script completion alone as proof:

adb shell
su
id

The root context is ephemeral and is lost on reboot. That behavior is important: this stage is an enabling primitive for the downgrade, not the final persistence mechanism or the bootloader unlock itself.

The successful run showed uid=0, changed SELinux to permissive for the temporary environment, mounted the temporary su, and disabled the Fire OS OTA packages handled by the tool.

GhostLock root shell showing uid 0 and OTA package changes

The full GhostLock exploit trace is retained as supporting evidence.

3. Downgrade the preloader

With temporary root available, I used the package's dedicated downgrade workflow instead of manually writing firmware partitions. This restored a preloader compatible with the existing Kamakiri path.

After the downgrade, the Fire TV intentionally stopped booting into Fire OS. In this specific workflow, that non-booting state is the expected handoff between the live-kernel stage and the USB BootROM stage. It must not be confused with proof that an arbitrary failed flash is recoverable.

Télécharger l’outil