Skip to content
KitploitKITPLOIT
StrumentiBlog
Log in
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
ghostlock-s26 — GhostLock (CVE-2026-43499) app for the Galaxy S26 series | Kitploit
Strumenti/GitHubGitHub/1ndevelopment/ghostlock-s26
Android SecurityPrivilege EscalationPersistence MechanismsExploitationMobile App PentestingPost-ExploitationMobile SecurityPayload Development
GitHub1ndevelopment/ghostlock-s26

ghostlock-s26

GhostLock (CVE-2026-43499) app for the Galaxy S26 series

Vedi Repository
9213311 giorni faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Contenuto non disponibile nella lingua richiesta. Visualizzazione della versione inglese.

GhostLock - Android wrapper (indev.ghostlock.s26)

One-click Android wrapper for polygraphene/ghostlock-s26: GhostLock (CVE-2026-43499) ported to the whole Samsung Galaxy S26 series (Android 16 / GKI 6.12). One APK, three kernel lines, runtime parameter matching - no per-build app variants.

Use only on devices you own or are explicitly authorized to test. Temp root vanishes on reboot. A second exploit run in the same boot can crash the device - reboot before retrying.

Disclaimer: experimenting with this software involves low-level kernel exploits, root, and boot-time claims. It is provided AS IS, without warranty of any kind. You use it entirely at your own risk; the author is not responsible for bricked, boot-looped, or otherwise damaged devices, or for any data loss, voided warranties, or damage arising from its use.

Coverage: the full S26 family

The exploit matches by kernel line, not by individual build (exploit/src/params_table.c is authoritative; ParamsTable.kt mirrors it for the UI verdict only):

Device codenameMarketingSoCKernel line
m1qGalaxy S26 (SM-S942x)Snapdragoncn or intl (by CSC)
m2qGalaxy S26+ (SM-S947x)Snapdragoncn or intl (by CSC)
m3qGalaxy S26 Ultra (SM-S948x)Snapdragoncn or intl (by CSC)
m1sGalaxy S26 (SM-S942B)Exynosexynos
m2sGalaxy S26+ (SM-S947B)Exynosexynos

Tested builds (17): S9420ZCS4AZG1, S9470ZCS4AZG1, S9480ZCS3AZF1, S9480ZCS4AZG1, S942BXXS4AZG5, S947BXXS3AZF1, S947BXXS4AZG5, S942QOPU1AZDE, S942U1UES4AZG3, S942USQS4AZG3, S947USQS4AZG3, S9480ZHS4AZG1, S948BXXS4AZG5/6, S948NKSS4AZG3, S948U1UES2AZE1, S948USQS4AZG3.

Unknown OTAs fall back exactly like upstream params.c: exact build first, then same model + 3-char CSC (OTA reuse), then latest same-device entry (flagged unverified), else fail-closed (the app shows UNSUPPORTED and the native layer exits 2). Completely unknown models are refused - never forced.

What the app does

One big button - Root my S26 - runs the whole pipeline and narrates into the Output card:

  1. Device check - model/device/incremental/fingerprint plus the series verdict (exact / OTA-reuse / unverified guess / unsupported). Unsupported builds stop here (fail-closed, no boot-claim burned).
  2. Shizuku - used automatically when connected (uid 2000 shell, same context family as the README's adb shell flow). Permission is requested once at launch (and again if the server restarts); the Root flow waits for the grant instead of bailing. If the server is down the app opens the Shizuku manager so you can start it, then falls back to the in-app shell. Adding the app to Shizuku's allowlist removes the prompt entirely.
  3. Stage - copies preload.so, su_daemon, ksud to /data/local/tmp (preload.so, cve-2026-43499-root, ksud) and chmods them. If you already adb pushed the files per the upstream README, they are picked up in place.
  4. Run - executes exactly what upstream documents: env LD_PRELOAD=/data/local/tmp/preload.so sh (the .so constructor runs the chain and _exits; stdout is the exploit log), up to 5 attempts - the race is probabilistic. A BOOT_FORCE=1 switch is available but rebooting is safer.
  5. Verify - confirms id reports uid=0 through any channel: temp-daemon socket first, then KernelSU-style su. This matters because on a full success su_daemon unlinks its socket and exits by design (handover to KernelSU) - a dead temp socket with working su means rooted, not broken. Prints the boot-claim log tail and reports rooted / exit-code advice.

Below that: a single command field + Run as root row (one-shot commands via the su daemon's C protocol; interactive PTY is out of scope for v1), and a small Reset link that clears /data/local/tmp/ghostlock-boot.log so a run can be retried without rebooting (upstream warns this may panic - reboot is the safe path).

Project layout

exploit/                  vendored upstream (Makefile + src/, authoritative)
ksud                      upstream prebuilt KernelSU loader (ARM64 PIE, also in assets)
app/src/main/assets/ksud  staged copy shipped in the APK
app/src/main/assets/      + preload.so / su_daemon after stage-assets.sh
app/src/main/cpp/         optional CMake rebuild of preload.so from exploit/src
app/src/main/java/indev/ghostlock/s26/
  MainActivity.kt         UI (device / stage / run / shell / boot guard)
  ParamsTable.kt          series table mirror (17 builds, 3 lines, 5 codenames)
  DeviceCompat.kt         Build.* identity + series verdict
  ShellRunner.kt          Shizuku (uid 2000) + local fallback, staging
  SuClient.kt             /data/local/tmp/temp_su.sock 'C'-mode client
  GhostlockManager.kt     exit-code interpreter (0/1/2/3/4)
PORTING.upstream.md       porting notes (new firmware = new device_map row)

Build

Requirements: Android Studio (JBR 21) / SDK 35 / NDK r26+ / CMake 3.22.1 / JDK 17.

# 1. Build the native payloads with the NDK (upstream flow):
cd exploit && make preload
#   -> build/bin/preload.so, build/embed/su_daemon_aarch64_pie

# 2. Stage them into the APK assets:
./stage-assets.sh

# 3. Build the app:
./gradlew :app:assembleDebug
#   -> app/build/outputs/apk/debug/app-debug.apk

ksud is already vendored (ksud + app/src/main/assets/ksud) so step 1–2 only produce the two NDK outputs. The CMake target in app/src/main/cpp/CMakeLists.txt can additionally rebuild libpreload.so from the same sources inside the APK as a fallback.

CI build (tailored to device / SoC)

The .github/workflows/build.yml workflow builds the app tailored to the target device codename / processor type - no SDK, NDK, or Docker needed locally. Fork the repo, then from the repo's Actions tab → GhostLock-S26 Device Build → Run workflow, then set:

InputChoiceDefaultEffect
deviceall / m1q / m2q / m3q / m1s / m2sallDevice codename (build target)
processorall / snapdragon / exynosallSoC family (filters kernel lines)
kernel_lineauto / cn / intl / exynosautoPin the exact params line (auto derives from device/processor)
tailoron / offoffPrune params_table.c + ParamsTable.kt to the selected device/line for a smaller single-target payload
build_typedebug / releasedebugAPK variant
rebuild_ksudon / offonRebuild ksud + kernelsu.ko from polygraphene/KernelSU at ksud_ref, or keep the vendored prebuilt
kmiandroid16-6.12 / android15-6.6android16-6.12KMI the module is compiled for (S26 = GKI 6.12)
samsung_hardeningon / offonCONFIG_KSU_SAMSUNG_KDP/RKP/DEFEX=y (Samsung kdp creds, RKP/DEFEX sync)
no_patch_texton / offoffDisable live text patching (Samsung Exynos EL2 targets)

Plus ksud_ref, ddk_release and ksu_manager_apk for pinning the KernelSU source ref / DDK image / bundled Manager APK, and sign_release to sign with the KEYSTORE_BASE64 / KEY_ALIAS / secrets.

For example, a Snapdragon-only Galaxy S26 Ultra build (kernel lines cn + intl, with the other devices pruned out) would be: device=m3q, processor=snapdragon, tailor=on.

Scarica lo strumento