
CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)
https://github.com/user-attachments/assets/f3d0858d-f8f5-444f-8ae5-541c2bc744c3
![]() |
![]() |
![]() |
![]() |
While this repository originated as a device-specific port for the Galaxy S22 Ultra, the project has since shifted and expanded to support all Samsung devices running the Linux Android 12 5.10 kernel.
The exploit framework accommodates both Qualcomm (e.g. Snapdragon 8 Gen 1 / SM8450) and Samsung Exynos (e.g. Exynos 2200) architectures, adapting kernel layouts, CFI dispatch, KASLR slide derivation, and race choreography to 5.10 GKI structures. Any Samsung device running a 5.10 kernel can be supported by extracting its symbols and struct layouts into a target folder under src/targets/<TARGET> using target_generator.
The following pre-configured target profiles are included in src/targets/<TARGET>. Each profile contains verified kernel offsets, structure layouts, and target configurations for that specific firmware release:
| Device | Model | Target / Build | SoC | Android | Region / Notes |
|---|---|---|---|---|---|
| Galaxy S22 | SM-S901B | S901BXXSNGZD7 | Samsung Exynos 2200 | Android 16 | Europe / International |
| Galaxy S22 | SM-S901E | S901EXXSEGZE3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | Global / Latin America / Asia / Africa |
| Galaxy S22 | SM-S901U1 | S901U1UESAGZF3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | USA (Factory Unlocked) |
| Galaxy S22 | SM-S901U1 | S901U1UESAGZH3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | USA (Factory Unlocked) |
| Galaxy S22 | SM-S901U | S901USQSAGZF3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | USA (Carrier Locked) |
| Galaxy S22 | SM-S901U | S901USQSAGZH3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | USA (Carrier Locked) |
| Galaxy S22 | SM-S901U | S901USQU2BVK1 | Qualcomm Snapdragon 8 Gen 1 | Android 13 | USA (Carrier Locked) |
| Galaxy S22 | SM-S901W | S901WVLS4DWL3 | Qualcomm Snapdragon 8 Gen 1 | Android 14 | Canada |
| Galaxy S22 | SM-S901W | S901WVLSAGZH3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | Canada |
| Galaxy S22+ | SM-S9060 | S9060ZCS9GZA1 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | China (CHC) |
| Galaxy S22+ | SM-S906E | S906EXXSEGZE3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | Global / Latin America / Asia / Africa |
| Galaxy S22 Ultra | SM-S908B | S908BXXSMGZB2 | Samsung Exynos 2200 | Android 16 | Europe / International |
| Galaxy S22 Ultra | SM-S908B | S908BXXSNGZD7 | Samsung Exynos 2200 | Android 16 | Europe / International |
| Galaxy S22 Ultra | SM-S908E | S908EXXSEGZE3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | Global / Latin America / Asia / Africa |
| Galaxy S22 Ultra | SM-S908N | S908NKSS9GZE5 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | South Korea |
| Galaxy S22 Ultra | SM-S908W | S908WVLS8FYG7 | Qualcomm Snapdragon 8 Gen 1 | Android 15 | Canada (Baseline Profile) |
| Galaxy S22 Ultra | SM-S908W | S908WVLSAGZE3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | Canada |
| Galaxy S22 Ultra | SCG14 | SCG14KDS1EZE3 | Qualcomm Snapdragon 8 Gen 1 | Android 16 | Japan (au KDDI) |
| Galaxy Tab S8 Ultra | SM-X900 | X900XXU9DYE5 | Qualcomm Snapdragon 8 Gen 1 | Android 15 | Global (Wi-Fi) |
[!NOTE] The offsets and structure layouts are specific to each target build. Always build with the matching
PROJECT=<TARGET>parameter for your device's exact firmware version.
This port is based on the exploit implementation published in:
b850d3bddc74c3328d5fbcc0568d21962b55d949Special thanks to:
The upstream Apache License 2.0 is retained in LICENSE, and attribution requirements are specified in NOTICE.
src/targets/<TARGET> with kernel structure layouts and offset generation via target_generator.exp32 route (or exp64 where applicable): futex choreography, 32-bit stack stamp, and sched_setattr run in an embedded child stage (src/exp32/).system_unbound_wq user-mode-helper root path and updated runtime SELinux enforcement target to selinux_state.enforcing./data/local/tmp/cve-2026-43499-root.cve43499-hold process after success
so dangling kernel references cannot be recycled into unrelated slab objects.Set ANDROID_NDK_HOME to Android NDK r27+ or a compatible toolchain, then run with your chosen PROJECT=<TARGET> from the table above:
# Example building for Galaxy S22 Ultra (SM-S908W):
make PROJECT=S908WVLS8FYG7 clean preload root-helper
# Or specify any target from the supported device list:
# make PROJECT=S901BXXSNGZD7 clean preload root-helper # Galaxy S22 (Exynos)
# make PROJECT=S906EXXSEGZE3 clean preload root-helper # Galaxy S22+ (Snapdragon)
# make PROJECT=X900XXU9DYE5 clean preload root-helper # Galaxy Tab S8 Ultra
To build for a QEMU environment running the Android kernel with a Buildroot filesystem:
make USE_BUILDROOT=1 PROJECT=<TARGET> clean preload root-helper
Outputs:
build/<TARGET>/bin/cve-2026-43499
build/<TARGET>/bin/cve-2026-43499-root
build/<TARGET>/bin/cve-exp32 (or cve-exp64 for 64-bit exp targets like BVK1)
Push the binaries built for your target to the device: