Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

ЛентыКонтактыКонфиденциальность© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
s9180-rootmygalaxy — RootMyGalaxy for Galaxy S23 Ultra SM-S9180 (FZG1) - temp root via CVE-2026-43499, KernelSU late-load, no partition flashing, no Knox | Kitploit
Инструменты/GitHubGitHub/deancyl/s9180-rootmygalaxy
Android SecurityPrivilege EscalationPersistence MechanismsExploitationMobile App PentestingReverse EngineeringMobile SecurityPayload Development
GitHubdeancyl/s9180-rootmygalaxy

s9180-rootmygalaxy

RootMyGalaxy for Galaxy S23 Ultra SM-S9180 (FZG1) - temp root via CVE-2026-43499, KernelSU late-load, no partition flashing, no Knox

21813 дней назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Репозиторий
Контент недоступен на запрошенном языке. Показываем английскую версию.

RootMyGalaxy for Galaxy S23 Ultra (SM-S9180 / FZG1)

Release repository for the RootMyGalaxy port and enhanced version targeting the Samsung Galaxy S23 Ultra (SM-S9180). Based on upstream BuSung-dev/Root-My-Galaxy v0.2.36, adapted for the S9180ZHS8FZG1 firmware, and providing an enhanced variant with embedded KernelSU v3.3.0.

⚠️ All versions in this repository are "in-memory temporary root": no partitions are flashed, the bootloader is not unlocked, and Knox e-fuse is not triggered. Root is lost after reboot, and the phone returns to a fully stock state.


📦 Releases

ReleaseDescriptionIntended for
v0.2.36-fzg1Original baseline: upstream 0.2.36 (a version verified to successfully achieve temporary root), with embedded KernelSU v3.2.5Those who want stability and just need it to work
v0.2.36-ksu330Enhanced variant: same baseline, with the embedded ksud swapped to KernelSU v3.3.0 (32601); everything else is byte-for-byte identicalThose who want the latest KernelSU

The exploit chain is completely identical between the two versions (byte-for-byte), the only difference being the late-loaded KernelSU version.

✅ Applicability (must verify)

ItemRequirement
DeviceSamsung Galaxy S23 Ultra SM-S9180 (Hong Kong/China mainland share the same hardware)
Firmware (PDA/CSC)S9180ZHS8FZG1 (FZG1)
OS versionOne UI 8.5 / Android 16
Kernel version5.15.189-android13-8-33413713-abS9180ZHS8FZG1
Security patch level (SPL)2026-07-05 (or earlier ZHS-series firmware)

❌ Not applicable

  • Any other device model (including unverified versions of firmware for other sales regions of the S23 Ultra)
  • Firmware with the 2026-08 security patch and later — CVE-2026-43499 (GhostLock) is expected to be patched in that batch, and this tool will be permanently disabled after upgrading
  • Devices that are already unlocked/flashed (untested, use at your own risk)

How to verify: Settings → About phone → Software information, confirm that "One UI version / Android version / Kernel version / Security patch level" match the table above; or adb shell getprop ro.build.fingerprint should contain S9180ZHS8FZG1.

🔧 How it works

  1. Exploits the kernel vulnerability CVE-2026-43499 (GhostLock) to obtain in-memory temporary root (uid=0)
  2. Loads the KernelSU module into the kernel via ksud using late-load (LKM) (manual relocation, no partition modification required)
  3. Throughout the process, SELinux remains Enforcing, Knox is unaffected, and there are no persistent writes

📲 Usage

  1. Download the APK from the Release and install it (you need to allow installation from unknown sources)
  2. Open the app and follow the on-screen prompts to trigger temporary root
  3. Open KernelSU Manager (for the v3.3.0 variant, use KernelSU v3.3.0 Manager) and confirm the status is "Working"
  4. Root is lost after reboot; when needed, just reopen the app and run it again

🧾 Checksums

v0.2.36-ksu330 (enhanced variant)

MD5    : 102f5dd4dbbab7fb7babbbb5a8bac8a2
SHA256 : 03135340607fba9d4f15c3183af62d83f64c87e311e8d6deef38de5edf9a8d00
Size   : 68,141,362 bytes

v0.2.36-fzg1 (original baseline)

MD5    : 3b334cdad520f5d6f990ae661661824b
SHA256 : 17a88b2ed053bc1e54439a841b744bb2ee10f4ab90492ad431827db1f390b457
Size   : 69,820,722 bytes

⚠️ Risk statement

  • This tool exploits a public kernel vulnerability to achieve temporary root. Any root operation carries risk, including but not limited to system instability, data loss, and a very small probability of device damage
  • Knox e-fuse will theoretically not be triggered (no partition flashing, no bootloader tampering), but the author is not responsible for any unintended consequences
  • The behavior of the kernel module after rooting (KDP/RKP/DEFEX interaction) has been tested on the target firmware, but behavior on other firmware versions is not guaranteed
  • Do not use this tool for illegal purposes; it is intended only for device owners to research and use on their own devices

📁 Repository structure

This repository not only publishes the APK but also fully hosts the source code and build chain, so you can clone it and reproduce all artifacts from scratch:

s9180-rootmygalaxy/
├── README.md                                    ← This file
├── LICENSE                                      ← GPL-3.0 (KernelSU derivative code)
├── modules/
│   └── rmg_memtonic/                            ← MemTonic memory maintenance module (v1.4.1)
│       Startup storm guardrail + screen-off memory maintenance: make way for the launcher during soft reboot,
│       smooth peaks for newly added apps, whitelist exemptions, structured logging; see modules/rmg_memtonic/README.md
├── docs/progress/                               ← Development progress records (sanitized)
├── patch/
│   └── KernelSU-v3.3.0-samsung-kdp-rkp-defex.patch
│       Core achievement: porting the Samsung KDP/RKP/DEFEX kernel hardening adaptation from v3.2.5
│       to the KernelSU v3.3.0 source tree (16 files, round-trip passes on a clean tree)
├── .github/workflows/
│   └── build.yml                                ← GitHub Actions build pipeline
│       (DDK container builds .ko + NDK r29 cross-compiles ksud, manually triggered)
├── scripts/
│   ├── 01-build-module.sh                       ← Build the kernel module locally (requires docker)
│   ├── 02-build-ksud.sh                         ← Cross-compile ksud locally (requires NDK, rust_embed embeds .ko)
│   ├── 03-audit-module.sh                       ← Symbol audit (hard gate: missing=0; tool auto-pulls from upstream)
│   ├── 04-deploy-device.ps1                     ← Real-device deployment (push ksud + exploit + late-load)
│   ├── build_fzg1_apk.py                        ← App repackaging: replace embedded payload/helper/feed
│   └── build_ksu330_apk.py                      ← App repackaging: upgrade embedded ksud to v3.3.0 (source of this repo's v0.2.36-ksu330)
└── docs/
    ├── BUILD.md                                 ← Build guide (Actions / local methods + known build pitfalls)
    └── VERIFY.md                                ← Real-device deployment and verification checklist (preheating/timing rules/troubleshooting)

Quick start (developers)

git clone https://github.com/deancyl/s9180-rootmygalaxy.git
cd s9180-rootmygalaxy
# For building, see docs/BUILD.md; for real-device verification, see docs/VERIFY.md

Origin and verification of binary artifacts

APK in ReleaseBuild methodVerification
rootmygalaxy-0.2.36-fzg1Upstream original (unmodified)See Release page
rootmygalaxy-0.2.36-ksu330scripts/build_ksu330_apk.py performs a minimal-difference replacement on the original (only the embedded ksud asset + feed size); 136 of all 139 entries are byte-for-byte identicalSee Release page

The app baseline comes from upstream Root-My-Galaxy (Apache-2.0), the kernel-side patch is derived from KernelSU (GPL-3.0), and the audit tool is taken from the upstream Payloads repository (Apache-2.0). For license attribution, see LICENSE and the notes above.

🙏 Acknowledgements

  • BuSung-dev/Root-My-Galaxy — upstream project
  • KernelSU — kernel-level root solution
  • The discoverer of CVE-2026-43499 (GhostLock)
Скачать инструмент