Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
opace6-cve-2026-64560 — Temporary root tool for OnePlus Ace 6 that exploits the CVE-2026-64560 Linux kernel POSIX CPU timer use-after-free to gain root until reboot, without modifying system partitions. | Kitploit
工具/GitHubGitHub/wangs-official/opace6-cve-2026-64560
Android SecurityPrivilege EscalationVulnerability AnalysisExploitationMobile App PentestingMobile SecurityPapers & ResearchPayload DevelopmentBinary Exploitation

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubwangs-official/opace6-cve-2026-64560

opace6-cve-2026-64560

Temporary root tool for OnePlus Ace 6 that exploits the CVE-2026-64560 Linux kernel POSIX CPU timer use-after-free to gain root until reboot, without modifying system partitions.

查看仓库
22天前尚未审核

OnePlus Ace 6 临时 Root 工具

通过 CVE-2026-64560(Linux 内核 POSIX CPU timer UAF)漏洞获取 OnePlus Ace 6 当前启动周期的临时 root 权限。重启后失效,不修改系统分区。

[!WARNING] 可能导致设备重启或数据丢失。仅在你自己的设备上使用,操作前请备份重要数据。

支持的设备

项目信息
设备OnePlus Ace 6 (OP6113L1)
固件指纹OnePlus/PLQ110/OP6113L1:16/BP2A.250605.015/...
内核版本6.6.118-android15-8-...

如果你的系统版本指纹不匹配,工具会拒绝运行并提示 TARGET_PROFILE_GATE_FAIL。

使用前准备

  1. 一台 OnePlus Ace 6,系统版本与上面匹配
  2. 一台电脑(Windows / macOS / Linux 均可)
  3. USB 数据线
  4. 手机已开启 USB 调试(设置 → 关于手机 → 连点版本号 7 次开启开发者选项 → 开发者选项 → USB 调试)
  5. 电脑已安装 adb(下载地址,解压后把路径加到系统 PATH)

步骤 1 — 下载工具

前往本仓库的 Releases 页面,下载最新版的 cve-2026-64560-fanout-opace6。

把下载的文件放到一个你记得住的位置,比如桌面。

步骤 2 — 连接设备

用 USB 线连接手机和电脑,手机上弹窗点「允许 USB 调试」。

打开终端(Windows 按 Win+R 输入 cmd 回车),验证设备已连接:

root@kitploit:~
adb devices

应该能看到你的设备序列号,状态为 device。如果显示 unauthorized,请在手机上点允许。

步骤 3 — 推送到手机

Windows:

root@kitploit:~
adb push C:\Users\你的用户名\Desktop\cve-2026-64560-fanout-opace6 /data/local/tmp/
adb shell chmod 777 /data/local/tmp/cve-2026-64560-fanout-opace6

macOS / Linux:

root@kitploit:~
adb push ~/Desktop/cve-2026-64560-fanout-opace6 /data/local/tmp/
adb shell chmod 777 /data/local/tmp/cve-2026-64560-fanout-opace6

注意: 必须给 777 权限,755 会报 Permission denied。

步骤 4 — 预检

先运行预检确认你的设备可以使用:

root@kitploit:~
adb shell /data/local/tmp/cve-2026-64560-fanout-opace6 --preflight

看到 PREFLIGHT_PASS 说明一切正常,可以继续。 看到 TARGET_PROFILE_GATE_FAIL 说明你的系统版本不匹配,无法使用。

步骤 5 — 运行

这个工具利用的是内核竞态条件,有概率性,可能需要多次尝试甚至多次重启。

方式 A:使用自动脚本(推荐)

自动脚本会帮你重试,包括自动重启设备、等待冷却、检测成功。

Windows:

把本仓库的 scripts\boot-campaign.bat 和下载的 payload 放在同一个文件夹, 然后在 CMD 中进入该文件夹运行:

root@kitploit:~
boot-campaign.bat -n 6

-n 6 表示最多重启 6 次尝试。脚本会自动:

  • 推送文件到手机
  • 运行预检
  • 运行 exploit 并实时显示进度(attempt 次数)
  • 如果失败,重启设备降温后重试
  • 成功后自动退出

macOS / Linux:

root@kitploit:~
sh scripts/boot-campaign.sh -p cve-2026-64560-fanout-opace6 -n 6

方式 B:手动运行

root@kitploit:~
adb shell /data/local/tmp/cve-2026-64560-fanout-opace6 --run

如果没有成功(没有看到 ROOT_SUCCESS),重启手机再试。建议等手机摸起来不烫了再试, CPU 温度过高会降低成功率。

步骤 6 — 使用 root

成功后会看到 ROOT_SUCCESS,此时打开一个新的终端窗口:

root@kitploit:~
adb shell /data/local/tmp/su

然后输入 id,如果看到 uid=0(root) 就说明已经获取 root 权限了。

重要: root 权限只在本次开机有效,手机重启后需要重新运行。 不会修改 boot、vendor、system 分区,不影响 OTA 更新。

常见问题

Q: Permission denied 怎么办? 执行 adb shell chmod 777 /data/local/tmp/cve-2026-64560-fanout-opace6。

Q: TARGET_PROFILE_GATE_FAIL 怎么办? 你的系统版本和这个工具不匹配。需要对应版本的适配。

Q: 跑了很久没反应? 这是正常的。exploit 是概率性的内核竞态,每次 attempt 需要 20-30 秒。 如果一轮(32 次 attempt)没命中,脚本会自动重启再试。多试几轮一般能成功。

Q: 手机重启了怎么办? 有时候 exploit 会触发内核 crash 导致重启,这是正常的,重新运行即可。

Q: 已经装了 KernelSU / Magisk 还能用吗? 如果改过内核(比如刷了 KSU),实际内核和原厂不同,可能会失败。建议用原厂 boot。

Q: 草稿状态是什么意思? 此适配尚未在 Ace 6 真机上完整验证,race 参数继承自 OP13,可能需要调优。 physical_delta 的 0x28000000 也需在真机上通过 --preflight 确认。

来源与许可

上游:NebuSec/CyberMeowfia。 具体修订和 Linux 修复见 docs/UPSTREAM.md。 Apache License 2.0;见 LICENSE 和 NOTICE。

下载工具