Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
도구/GitHubGitHub/sarabpal-dev/ionstack-s22u
Android SecurityPrivilege EscalationExploitationPost-ExploitationMobile SecurityBinary Exploitation
GitHubsarabpal-dev/ionstack-s22u

IonStack-S22U

CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)

저장소 보기
7934157일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-43499 - Samsung 5.10 Kernel Devices (IonStack)

https://github.com/user-attachments/assets/f3d0858d-f8f5-444f-8ae5-541c2bc744c3

While this repository originated as a device-specific port for the Galaxy S22 Ultra, the project has since shifted and expanded to support all Samsung devices running the Linux Android 12 5.10 kernel.

The exploit framework accommodates both Qualcomm (e.g. Snapdragon 8 Gen 1 / SM8450) and Samsung Exynos (e.g. Exynos 2200) architectures, adapting kernel layouts, CFI dispatch, KASLR slide derivation, and race choreography to 5.10 GKI structures. Any Samsung device running a 5.10 kernel can be supported by extracting its symbols and struct layouts into a target folder under src/targets/<TARGET> using target_generator.

Supported Devices & Targets

The following pre-configured target profiles are included in src/targets/<TARGET>. Each profile contains verified kernel offsets, structure layouts, and target configurations for that specific firmware release:

DeviceModelTarget / BuildSoCAndroidRegion / Notes
Galaxy S22SM-S901BS901BXXSNGZD7Samsung Exynos 2200Android 16Europe / International
Galaxy S22SM-S901ES901EXXSEGZE3Qualcomm Snapdragon 8 Gen 1Android 16Global / Latin America / Asia / Africa
Galaxy S22SM-S901U1S901U1UESAGZF3Qualcomm Snapdragon 8 Gen 1Android 16USA (Factory Unlocked)
Galaxy S22SM-S901U1S901U1UESAGZH3Qualcomm Snapdragon 8 Gen 1Android 16USA (Factory Unlocked)
Galaxy S22SM-S901US901USQSAGZF3Qualcomm Snapdragon 8 Gen 1Android 16USA (Carrier Locked)
Galaxy S22SM-S901US901USQSAGZH3Qualcomm Snapdragon 8 Gen 1Android 16USA (Carrier Locked)
Galaxy S22SM-S901US901USQU2BVK1Qualcomm Snapdragon 8 Gen 1Android 13USA (Carrier Locked)
Galaxy S22SM-S901WS901WVLS4DWL3Qualcomm Snapdragon 8 Gen 1Android 14Canada
Galaxy S22SM-S901WS901WVLSAGZH3Qualcomm Snapdragon 8 Gen 1Android 16Canada
Galaxy S22+SM-S9060S9060ZCS9GZA1Qualcomm Snapdragon 8 Gen 1Android 16China (CHC)
Galaxy S22+SM-S906ES906EXXSEGZE3Qualcomm Snapdragon 8 Gen 1Android 16Global / Latin America / Asia / Africa
Galaxy S22 UltraSM-S908BS908BXXSMGZB2Samsung Exynos 2200Android 16Europe / International
Galaxy S22 UltraSM-S908BS908BXXSNGZD7Samsung Exynos 2200Android 16Europe / International
Galaxy S22 UltraSM-S908ES908EXXSEGZE3Qualcomm Snapdragon 8 Gen 1Android 16Global / Latin America / Asia / Africa
Galaxy S22 UltraSM-S908NS908NKSS9GZE5Qualcomm Snapdragon 8 Gen 1Android 16South Korea
Galaxy S22 UltraSM-S908WS908WVLS8FYG7Qualcomm Snapdragon 8 Gen 1Android 15Canada (Baseline Profile)
Galaxy S22 UltraSM-S908WS908WVLSAGZE3Qualcomm Snapdragon 8 Gen 1Android 16Canada
Galaxy S22 UltraSCG14SCG14KDS1EZE3Qualcomm Snapdragon 8 Gen 1Android 16Japan (au KDDI)
Galaxy Tab S8 UltraSM-X900X900XXU9DYE5Qualcomm Snapdragon 8 Gen 1Android 15Global (Wi-Fi)

[!NOTE] The offsets and structure layouts are specific to each target build. Always build with the matching PROJECT=<TARGET> parameter for your device's exact firmware version.

Reference source

This port is based on the exploit implementation published in:

  • NebuSec/CyberMeowfia — IonStack/CVE-2026-43499/exploit
  • BuSung-dev/CVE-2026-43499-S25U
  • Upstream revision used as the porting base: b850d3bddc74c3328d5fbcc0568d21962b55d949

Special thanks to:

  • F-19-F/IonStackQuest3

The upstream Apache License 2.0 is retained in LICENSE, and attribution requirements are specified in NOTICE.

Main porting changes

  • Ported exploit from v6.6 kernel (Galaxy S25 Ultra) to the Android v5.10 kernel architecture (supporting all Samsung 5.10 devices across Qualcomm and Exynos).
  • Added modular target profiles under src/targets/<TARGET> with kernel structure layouts and offset generation via target_generator.
  • Replaced the pselect race with the exp32 route (or exp64 where applicable): futex choreography, 32-bit stack stamp, and sched_setattr run in an embedded child stage (src/exp32/).
  • Added tracefs-based automatic KASLR slide recovery for the Samsung kernel.
  • Ported fake PI waiter/task layout, CFI/FOPS stage, and physical read/write primitive for v5.10.
  • Added a KDP-safe system_unbound_wq user-mode-helper root path and updated runtime SELinux enforcement target to selinux_state.enforcing.
  • Added a socket-backed root command helper at /data/local/tmp/cve-2026-43499-root.
  • Restores the global ashmem FOPS pointer immediately after establishing the arbitrary read/write primitive.
  • Retains reclaimed pages in a detached cve43499-hold process after success so dangling kernel references cannot be recycled into unrelated slab objects.
  • Runs failed race attempts in independent child processes and automatically retries with a device-tuned delay sequence.

Build

Set ANDROID_NDK_HOME to Android NDK r27+ or a compatible toolchain, then run with your chosen PROJECT=<TARGET> from the table above:

# Example building for Galaxy S22 Ultra (SM-S908W):
make PROJECT=S908WVLS8FYG7 clean preload root-helper

# Or specify any target from the supported device list:
# make PROJECT=S901BXXSNGZD7 clean preload root-helper   # Galaxy S22 (Exynos)
# make PROJECT=S906EXXSEGZE3 clean preload root-helper   # Galaxy S22+ (Snapdragon)
# make PROJECT=X900XXU9DYE5 clean preload root-helper    # Galaxy Tab S8 Ultra

To build for a QEMU environment running the Android kernel with a Buildroot filesystem:

  • Buildroot Toolchain Release: Download toolchain from sarabpal-dev/qemu Release (samsung-v1)
  • QEMU Kernel Execution Guide: Setup and run guide at QEMU Samsung README
make USE_BUILDROOT=1 PROJECT=<TARGET> clean preload root-helper

Outputs:

build/<TARGET>/bin/cve-2026-43499
build/<TARGET>/bin/cve-2026-43499-root
build/<TARGET>/bin/cve-exp32 (or cve-exp64 for 64-bit exp targets like BVK1)

Deploy

Push the binaries built for your target to the device:

도구 다운로드