
Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM
Ports of the CVE-2026-43499 payload (UAF → KernelSU LKM temporary root) for Samsung Galaxy S23 Ultra SM-S9180 (dm3q).
5.15.189-android13-8-33413713-abS9180ZHS8FZG1 (2026-07-05 security patch)su -c id → uid=0(root) context=u:r:ksu:s0, ksud 3.2.5| File | Description |
|---|---|
RootMyGalaxy-S9180-FZG1.apk | Signed APK (v3, CN=RMG), installable, contains payload |
cve-2026-43499-app.so | Patched payload, md5 ad6306e330897aa6b85b8badea1d60f7 |
fzg1-patch-spec.json | 6 movz patches applied to the FZF5 fork payload |
target.h | FZG1 target profile with corrected offsets |
ISSUE.md | Issue/port report for the upstream repo (BuSung-dev/Root-My-Galaxy-Payloads) |
Only 3 data symbols changed between FZF5 and FZG1 (all shifted +0x5c0):
| Symbol | FZF5 | FZG1 |
|---|---|---|
kmalloc_caches | 0x020641f8 | 0x020647b8 |
anon_pipe_buf_ops | 0x01e7f1e0 | 0x01e7f7a0 |
ashmem_fops | 0x0200d238 | 0x0200d7f8 |
All other symbols (ashmem family, init_task, prepare_kernel_cred, etc.) are unchanged. The movz migration is only 6 patches:
0x0067ec: 0xd238 -> 0xd7f8 (ashmem_fops)
0x007470: 0xf1e0 -> 0xf7a0 (anon_pipe_buf_ops)
0x00754c: 0xf1e0 -> 0xf7a0 (anon_pipe_buf_ops)
0x00765c: 0xf1e0 -> 0xf7a0 (anon_pipe_buf_ops)
0x0078ac: 0x41f8 -> 0x47b8 (kmalloc_caches)
0x007af4: 0xf1e0 -> 0xf7a0 (anon_pipe_buf_ops)
Working port for the Chinese firmware — see CHC-README.md
for the full port notes, including the CHC kallsyms off-by-one name-shift trap
and the 10 corrected data-symbol addresses.
| File | Description |
|---|---|
RootMyGalaxy-S9180-CHC.apk | Signed APK (v3, CN=RMG), installable, contains the CHC payload |
cve-2026-43499-chc-app.so | Patched CHC payload, md5 5292cdf88e64cf54bd1b4b44f63e45ed |
chc-patch-spec.json | 10 movz patches applied to the working TGY FZG1 payload |
chc-target.h | CHC target profile with corrected offsets |
5.15.189-android13-8-3251900-abS9180ZCS8FZG1 (build 3251900)The follow-up CHC firmware (kernel built Aug 12 2026, same version string) was disassembled
against ZG1: remove_waiter() is instruction-identical (1331 insns, 0 structural diffs) and
rt_mutex_start_proxy_lock / task_blocks_on_rt_mutex are byte-identical — the upstream fix
3bfdc63936dd is absent. Only the rodata region was rebuilt, shifting 3 data symbols by −0xC0.
Root verified working on ZH3 with the ported payload.
| File | Description |
|---|---|
RootMyGalaxy-S9180-CHC-ZH3.apk | Signed APK (v3, CN=RMG) for S9180ZCS8FZH3 |
cve-2026-43499-chc-zh3-app.so | ZH3 payload, md5 d7de6cebf66975f40d7d301fe2f0d7f3 |
chc-zh3-patch-spec.json | 6 movz patches (3 symbols shifted −0xC0) |
# 1. Install the APK matching your firmware
adb install -r RootMyGalaxy-S9180-FZG1.apk # TGY S9180ZHS8FZG1
adb install -r RootMyGalaxy-S9180-CHC.apk # CHC S9180ZCS8FZG1
adb install -r RootMyGalaxy-S9180-CHC-ZH3.apk # CHC S9180ZCS8FZH3
# 2. Launch the app and run the exploit (one attempt)
# Root is temporary: re-run the exploit after every full reboot.
pm install (SIGKILL) — use KernelSU su (u:r:ksu:s0).