Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
IonStack-S22U — CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel) | Kitploit
ツール/GitHubGitHub/sarabpal-dev/ionstack-s22u
Android SecurityPrivilege EscalationExploitationPost-ExploitationMobile SecurityBinary Exploitation
GitHubsarabpal-dev/ionstack-s22u

IonStack-S22U

CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)

リポジトリを見る
7934157日前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。

CVE-2026-43499 - Samsung 5.10 Kernel Devices (IonStack)

https://github.com/user-attachments/assets/f3d0858d-f8f5-444f-8ae5-541c2bc744c3

While this repository originated as a device-specific port for the Galaxy S22 Ultra, the project has since shifted and expanded to support all Samsung devices running the Linux Android 12 5.10 kernel.

The exploit framework accommodates both Qualcomm (e.g. Snapdragon 8 Gen 1 / SM8450) and Samsung Exynos (e.g. Exynos 2200) architectures, adapting kernel layouts, CFI dispatch, KASLR slide derivation, and race choreography to 5.10 GKI structures. Any Samsung device running a 5.10 kernel can be supported by extracting its symbols and struct layouts into a target folder under src/targets/<TARGET> using target_generator.

Supported Devices & Targets

The following pre-configured target profiles are included in src/targets/<TARGET>. Each profile contains verified kernel offsets, structure layouts, and target configurations for that specific firmware release:

DeviceModelTarget / BuildSoCAndroidRegion / Notes
Galaxy S22SM-S901BS901BXXSNGZD7Samsung Exynos 2200Android 16Europe / International
Galaxy S22SM-S901ES901EXXSEGZE3Qualcomm Snapdragon 8 Gen 1Android 16Global / Latin America / Asia / Africa
Galaxy S22SM-S901U1S901U1UESAGZF3Qualcomm Snapdragon 8 Gen 1Android 16USA (Factory Unlocked)
Galaxy S22SM-S901U1S901U1UESAGZH3Qualcomm Snapdragon 8 Gen 1Android 16USA (Factory Unlocked)
Galaxy S22SM-S901US901USQSAGZF3Qualcomm Snapdragon 8 Gen 1Android 16USA (Carrier Locked)
Galaxy S22SM-S901US901USQSAGZH3Qualcomm Snapdragon 8 Gen 1Android 16USA (Carrier Locked)
Galaxy S22SM-S901US901USQU2BVK1Qualcomm Snapdragon 8 Gen 1Android 13USA (Carrier Locked)
Galaxy S22SM-S901WS901WVLS4DWL3Qualcomm Snapdragon 8 Gen 1Android 14Canada
Galaxy S22SM-S901WS901WVLSAGZH3Qualcomm Snapdragon 8 Gen 1Android 16Canada
Galaxy S22+SM-S9060S9060ZCS9GZA1Qualcomm Snapdragon 8 Gen 1Android 16China (CHC)
Galaxy S22+SM-S906ES906EXXSEGZE3Qualcomm Snapdragon 8 Gen 1Android 16Global / Latin America / Asia / Africa
Galaxy S22 UltraSM-S908BS908BXXSMGZB2Samsung Exynos 2200Android 16Europe / International
Galaxy S22 UltraSM-S908BS908BXXSNGZD7Samsung Exynos 2200Android 16Europe / International
Galaxy S22 UltraSM-S908ES908EXXSEGZE3Qualcomm Snapdragon 8 Gen 1Android 16Global / Latin America / Asia / Africa
Galaxy S22 UltraSM-S908NS908NKSS9GZE5Qualcomm Snapdragon 8 Gen 1Android 16South Korea
Galaxy S22 UltraSM-S908WS908WVLS8FYG7Qualcomm Snapdragon 8 Gen 1Android 15Canada (Baseline Profile)
Galaxy S22 UltraSM-S908WS908WVLSAGZE3Qualcomm Snapdragon 8 Gen 1Android 16Canada
Galaxy S22 UltraSCG14SCG14KDS1EZE3Qualcomm Snapdragon 8 Gen 1Android 16Japan (au KDDI)
Galaxy Tab S8 UltraSM-X900X900XXU9DYE5Qualcomm Snapdragon 8 Gen 1Android 15Global (Wi-Fi)

[!NOTE] The offsets and structure layouts are specific to each target build. Always build with the matching PROJECT=<TARGET> parameter for your device's exact firmware version.

Reference source

This port is based on the exploit implementation published in:

  • NebuSec/CyberMeowfia — IonStack/CVE-2026-43499/exploit
  • BuSung-dev/CVE-2026-43499-S25U
  • Upstream revision used as the porting base: b850d3bddc74c3328d5fbcc0568d21962b55d949

Special thanks to:

  • F-19-F/IonStackQuest3

The upstream Apache License 2.0 is retained in LICENSE, and attribution requirements are specified in NOTICE.

Main porting changes

  • Ported exploit from v6.6 kernel (Galaxy S25 Ultra) to the Android v5.10 kernel architecture (supporting all Samsung 5.10 devices across Qualcomm and Exynos).
  • Added modular target profiles under src/targets/<TARGET> with kernel structure layouts and offset generation via target_generator.
  • Replaced the pselect race with the exp32 route (or exp64 where applicable): futex choreography, 32-bit stack stamp, and sched_setattr run in an embedded child stage (src/exp32/).
  • Added tracefs-based automatic KASLR slide recovery for the Samsung kernel.
  • Ported fake PI waiter/task layout, CFI/FOPS stage, and physical read/write primitive for v5.10.
  • Added a KDP-safe system_unbound_wq user-mode-helper root path and updated runtime SELinux enforcement target to selinux_state.enforcing.
  • Added a socket-backed root command helper at /data/local/tmp/cve-2026-43499-root.
  • Restores the global ashmem FOPS pointer immediately after establishing the arbitrary read/write primitive.
  • Retains reclaimed pages in a detached cve43499-hold process after success so dangling kernel references cannot be recycled into unrelated slab objects.
  • Runs failed race attempts in independent child processes and automatically retries with a device-tuned delay sequence.

Build

Set ANDROID_NDK_HOME to Android NDK r27+ or a compatible toolchain, then run with your chosen PROJECT=<TARGET> from the table above:

# Example building for Galaxy S22 Ultra (SM-S908W):
make PROJECT=S908WVLS8FYG7 clean preload root-helper

# Or specify any target from the supported device list:
# make PROJECT=S901BXXSNGZD7 clean preload root-helper   # Galaxy S22 (Exynos)
# make PROJECT=S906EXXSEGZE3 clean preload root-helper   # Galaxy S22+ (Snapdragon)
# make PROJECT=X900XXU9DYE5 clean preload root-helper    # Galaxy Tab S8 Ultra

To build for a QEMU environment running the Android kernel with a Buildroot filesystem:

  • Buildroot Toolchain Release: Download toolchain from sarabpal-dev/qemu Release (samsung-v1)
  • QEMU Kernel Execution Guide: Setup and run guide at QEMU Samsung README
make USE_BUILDROOT=1 PROJECT=<TARGET> clean preload root-helper

Outputs:

build/<TARGET>/bin/cve-2026-43499
build/<TARGET>/bin/cve-2026-43499-root
build/<TARGET>/bin/cve-exp32 (or cve-exp64 for 64-bit exp targets like BVK1)

Deploy

Push the binaries built for your target to the device:

ツールをダウンロード