CVE-2026-43499 is a use-after-free vulnerability in the Linux kernel real-time mutex implementation. During proxy-lock rollback in rt_mutex_start_proxy_lock(), invoked through futex_requeue(), remove_waiter() incorrectly operates on current rather than waiter::task. These tasks can differ in the proxy-lock path. Consequently, waiter dequeue operations occur without holding the affected task's pi_lock, its pi_blocked_on state remains uncleared with a dangling pointer, and rt_mutex_adjust_prio_chain() processes the wrong waiter task. Subsequent priority-inheritance chain traversal can dereference freed memory. A local unprivileged process can reach the affected functionality through priority-inheritance futexes, potentially enabling privilege escalation or kernel-level code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
38 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (143 hidden).
The supplied 100-file snapshot represents an Android root-exploitation application, not merely a vulnerability scanner. It includes 18 Kotlin source files, three AIDL interfaces, one Kotlin Gradle build script, and one shell script containing embedded Python; the workflow also embeds build automation. Most remaining files are HOCON kernel profiles, documentation, and configuration. Repository URL, analyzed git reference, and archive size were not provided; empty strings and zero are placeholders rather than known metadata. Several source files are truncated, and the documented C++23 native runtime in src/core/ and Rust extractor in tools/extract_rs/ are not included, limiting independent verification. The documented backend targets CVE-2026-43499 through a two-core PI-futex waiter race. KernelSnitch supplies kernel-memory discovery, while profiles contain KASLR anchors, credential templates, and task/security offsets. Three routes are described: multicast_waiter for selected 5.15 builds, TCP_ZEROCOPY_RECEIVE for compact-waiter 6.1 builds, and select_stack for tree-waiter 6.6/6.12 builds. Intended stages modify SELinux enforcement, elevate credentials to uid 0, and remove seccomp before root-child handoff. The TCP and multicast mechanisms are local kernel exploitation techniques, not evidence of remote network exploitation. CVE-2026-64560 appears only as an unavailable placeholder backend, not an implemented target. CVE attribution and device-success claims are repository assertions, not externally validated findings. The Android layer handles profile loading, merging, sparse overrides, imports, validation, GLK1 binary serialization, process orchestration, Shizuku integration, and logs. AIDL exposes runExploit with CPU, safety, force-attack, profile, and callback parameters. Runtime profiles are selected by exact kernel release; templates are excluded from automatic support matching. OTA tooling fetches user-selected HTTP(S) byte ranges, parses ZIP/ZIP64 and payload protobuf metadata, and extracts boot/xbl_config images. The XZ decoder explicitly skips integrity verification. CI builds the APK, native runtime, and cross-platform extractors, exports binary profiles, and publishes artifacts through GitHub releases and optional Telegram uploads. No fixed victim IP, remote attack service, reverse shell, C2 channel, or victim-data exfiltration is visible; Telegram traffic is attributable to CI artifact distribution. A notable safety issue is the 6.12.58-android16-6-gff10eaa8f8a4-ab15575650-4k profile: its comments document unsupported W1 execution and repeated kernel panics, yet index.conf still registers it. However, the visible controller also adds KnownUnrunnableReleases entries to invalidPaths. Because that mapping and downstream execution checks are truncated, the comments' claim that index registration alone makes this device runnable cannot be confirmed and may be stale. Another 5.15.189 profile explicitly awaits full device validation. Consequently, the listed kernel versions identify exact-build profile coverage, not universal vulnerable ranges or guaranteed successful exploitation.
This is a functional Android ARM64 local-kernel privilege-escalation repository, not merely a detector or documentation. It is a device-specific port of GhostLock targeting CVE-2026-43499 on the vivo iQOO Neo7 MT6983T Android 15 kernel 5.10.233 build. The C exploit in exploit/src/ uses a futex PI requeue/rt_mutex remove_waiter use-after-free to leave a stale rt_mutex_waiter pointer on a kernel stack. It stamps a forged waiter through an IPv6 TCP multicast setsockopt stack-copy carrier, then drives rt_mutex priority-chain processing to reach an rb_erase-derived 8-byte arbitrary kernel write. It retargets the boot_id ctl_table data pointer, using /proc/sys/kernel/random/boot_id as a kernel memory read/write primitive. The chain derives the KASLR slide using perf sampling with KernelSnitch as a supplemental technique, finds a controlled anchor task, overwrites its cred pointer with init_cred, and can alter the SELinux enforcement byte. The post-exploitation chain executes ksu/ksu_loader.sh in a privileged execution window, disables kptr_restrict, dumps runtime kallsyms, and waits for host-side Python scripts to rewrite the SakiSU module vermagic and resolve unexported symbols as SHN_ABS entries. It then loads the patched module with insmod, yielding a KernelSU/SakiSU-managed root environment. The repository contains 19 legacy Honor 80 GT target offset headers plus the primary exploit/src/targets/mt6983t-gl-5.10.233/target.h profile. Build support consists of an Android NDK Makefile and Docker helper. Automation is supplied through Windows batch/PowerShell scripts, while documentation describes deployment, recovery behavior, SELinux and ashmem remediation, and the non-persistent nature of root. Failed attempts may kill processes, corrupt the temporary boot_id route, or reboot/hang the device; the exploit is highly version- and layout-dependent.
This 56-file repository is a device-specific Android local-root payload suite for CVE-2026-43499. Its primary target is the Samsung Galaxy S25 Ultra SM-S938N (KOO) on firmware S938NKSUCDZIF and the exact Android 6.6.127 kernel identified in the target header and support feed. The main native implementation is in src/: main.c coordinates the futex PI race; slide.c derives the kernel slide through tracefs; fops.c and util.c create/verify configfs- and ashmem-based kernel access primitives; pipe.c implements pipe-backed physical read/write; root.c constructs a kernel workqueue/call_usermodehelper escalation route; preload.c supervises retry attempts; and su_daemon.c provides the root helper and local Unix-socket protocol. The Makefile builds an ARM64 app shared object, alternate release/stable variants, and a root helper. The repository also includes a paired KernelSU-Next v3.4.0 build and Samsung KDP/RKP/DEFEX patches, plus dfroot-lkm/dirtyfrag.c, a standalone privileged kernel module. That module disables SELinux enforcement, uses kprobes to bypass DEFEX checks, stages the selected daemon, invokes its late-load action from kernel context, and drops /dev/dfm0 or /dev/dfm1 status markers. Python tooling validates modules and pairs, derives feed entries, verifies release/version consistency, rebuilds artifacts, and publishes hashes/URLs. GitHub Actions build the native payload, KernelSU pairs, and KMI-specific DFRoot modules. Documentation is unusually explicit that the exact-target app payload and paired artifacts are build-verified but not yet proven by a fresh end-to-end handset run; it should therefore be treated as operational exploit code with unconfirmed target reliability rather than a broadly validated universal root.
This is a real, device-specific Android local privilege-escalation repository rather than a detection utility. Its principal payload is an AArch64 shared object, cve-2026-43499-app.so, built from the C sources under src/ for a single Samsung Galaxy S25 Ultra SM-S938N firmware/kernel profile. The Makefile builds the app payload, a non-app preload variant, and a cve-2026-43499-root helper. The payload uses CVE-2026-43499's futex priority-inheritance/requeue path, heap grooming and KernelSnitch timing logic, tracefs-based KASLR-slide recovery, configfs/ashmem corruption, pipe-buffer manipulation, and kernel physical read/write primitives. It then attempts to create a forged workqueue/call_usermodehelper request to execute the root helper and expose a local root service over a Unix socket. The hard-coded target profile in src/targets/pa3q-S938NKSUCDZIF/target.h binds the exploit to Android 17, firmware S938NKSUCDZIF, and kernel 6.6.127-android15-8-p33f4ffe-abogkiS938NKSUCDZIF-4k. It includes exact symbols, structure offsets, event IDs, physical/direct-map assumptions, and a P0 slide fingerprint table. Repository documentation explicitly states that compilation/feed checks passed but full handset validation remains pending; the physical kernel load address, skb allocation delta, and portions of the runtime path are not fully confirmed. A separate dfroot-lkm/ component builds dirtyfrag.ko for multiple Android KMIs. On load, it disables SELinux enforcement, installs kprobes to bypass Samsung DEFEX functions, copies a staged KernelSU daemon, runs its late-load command in kernel context, writes /dev/dfm0 or /dev/dfm1 status markers, and intentionally returns an error to unload. The kernelsu/ patch and automation build a Samsung KDP/RKP/DEFEX-compatible official KernelSU v3.3.0 module/daemon pair. support/targets-v3.json is the distribution feed and identifies the published exploit and KernelSU artifacts, including expected sizes and SHA-256 values. The tools/ directory contains Python/Perl tooling for target-pair verification, artifact/feed publication, KernelSU patch rebasing, and CI validation; GitHub Actions workflows automate Android NDK payload builds and KernelSU/module builds.
This is a standalone, device- and firmware-specific Android local-root repository rather than a Metasploit/Nuclei-style framework module. Its main deliverable is an AArch64 shared library named cve-2026-43499-app.so, built from src/ using the Android NDK; src/preload.c runs it through a constructor/supervisor and src/su_daemon.c builds the companion root-service helper. The primary C chain uses futex PI/requeue manipulation, KernelSnitch-assisted heap placement, ashmem/configfs file-operations corruption, pipe-buffer-based kernel memory read/write, tracefs/P0-based KASLR discovery, and a forged workqueue/usermodehelper path to execute the helper as root. It can then expose a local UNIX socket and stage KernelSU-Next artifacts. The repository contains firmware offsets and fingerprint data only for Samsung SM-S938N firmware S938NKSUCDZIF and its exact 6.6.127 Android kernel. Its target header hardcodes kernel object offsets, a physical-load candidate, trace event identifiers, and slide fingerprints. Documentation is internally cautious: CI compilation and paired KernelSU artifact verification succeeded, but the port report says the payload and several required runtime assumptions have not been exercised successfully on the handset. A separate dfroot-lkm/ component builds a DFRoot-derived kernel module for multiple Android KMIs. That module disables SELinux, installs DEFEX-bypassing kprobes, stages and invokes a KernelSU daemon from kernel context, writes /dev/dfm0 or /dev/dfm1 status markers, and intentionally self-unloads by returning -E2BIG. kernelsu/ contains Samsung KDP/RKP/DEFEX compatibility patches and verification tooling for KernelSU-Next v3.4.0. support/targets-v3.json is the one-entry artifact feed, while GitHub Actions workflows compile payloads, KernelSU pairs, and DFRoot modules. Python tools validate module compatibility, artifact versions, checksums, feed entries, and patch rebases.
GhostLock is a native C local privilege-escalation exploit targeting the claimed CVE-2026-43499 futex Priority Inheritance use-after-free on one specifically profiled POCO M7 5G Android 14 kernel. It is not a framework module or a detection-only repository. The 22-file repository consists of a README, build ignore rules, 12 primary core C/header components, KernelSnitch futex-collision helpers, and device-specific offset tables for the POCO flame kernel. core/main.c is the entry point and selects an exact uname release from devices/offsets.h before orchestrating exploitation. The core race uses FUTEX_WAIT_REQUEUE_PI, FUTEX_CMP_REQUEUE_PI, pselect6 fd-set copying, and sched_setattr to overwrite fields in a dangling on-stack rt_mutex_waiter and produce controlled kernel writes. core/slide.c uses that primitive to redirect the boot_id sysctl data source and leak a kernel pointer/KASLR slide. core/fops.c builds a fake file_operations route using ashmem and configfs callbacks to obtain kernel read/write access. core/pipe_physrw.c upgrades this into arbitrary byte-level kernel physical-memory access by locating and forging pipe_buffer structures; core/pipe.c contains an alternate/related pipe shaping implementation. core/sysctl.c implements a credential/SELinux escalation route using the boot_id disclosure mechanism. core/root.c locates the process task and modifies credential and SELinux-related state. A second post-exploitation mechanism in core/umh_root.c injects a fake work item into system_unbound_wq so the kernel executes /data/local/tmp/a/e with root credentials, after which it invokes /system/bin/sh and a root script. core/miniadb.c is an optional minimal ADB client that connects only to 127.0.0.1 on TCP port 5555 and authenticates using a locally stored RSA key. The implementation has hard-coded kernel symbols, structure offsets, physical memory mappings, and timing values, making it operational but highly device/kernel-specific rather than broadly weaponized.
This is a 37-file Rust workspace implementing an operational host-side orchestration tool for alleged CVE-2026-43499 exploitation of bootloader-locked vivo/iQOO Android devices. The workspace comprises `rmv-core` (exploit pipeline, payload catalog, fingerprint validation, cleanup, root and KernelSU logic, and ADB transports), `rmv-cli` (the `rmv` command-line frontend), and `rmv-wasm` (a limited browser WebUSB bridge). The primary desktop entry point is `crates/rmv-cli/src/main.rs`. The engine obtains device properties and `/proc/version`, blocks patched or unsupported Linux kernel builds, resolves a matching payload from a GitHub/jsDelivr catalog or local source, verifies SHA-256 and embedded `abogki*` identifiers, deploys a `preload.so` payload under `/data/local/tmp/rmv`, and monitors for UID 0. On success it optionally extracts `libksud.so` from an installed or supplied manager APK, runs KernelSU/SukiSU late-loading, repairs selected su paths, and removes artifacts. It supports native USB ADB, Android Wireless Debugging with mDNS/TLS/SPAKE2 pairing, external ADB CLI fallback, and WebUSB device inspection. No exploit shared object or kernel exploit source is present in this repository; exploitation depends on externally supplied or downloaded payload binaries.
This is a 52-file, standalone AArch64 Android local privilege-escalation repository for CVE-2026-43499 (“GhostLock”), described as a futex priority-inheritance use-after-free. It is not a Metasploit/Nuclei-style framework module. The primary runtime artifact is a target-specific preload shared object built from C and AArch64 assembly; its constructor in src/preload.c runs when injected through LD_PRELOAD. src/main.c coordinates the futex PI race, while src/slide.c leaks the KASLR base and src/fops.c, src/pipe.c, and src/util.c build forged file-operations and pipe-buffer primitives for arbitrary kernel memory access. src/root.c locates and overwrites the invoking process’s credentials, capabilities, SELinux data, and related state to obtain root; src/posture.c then suppresses kernel panic controls. The payload has a concrete post-exploitation component: CMake builds src/su_daemon.c as a PIE binary, src/su_blob.S embeds it into the preload library, and the successful root child writes it to /data/local/tmp/su before launching a Unix-socket daemon at /data/local/tmp/temp_su.sock. The daemon can also forward requests to /system/bin/su if KernelSU is present. The implementation includes retry logic, process/CPU affinity and resource-limit setup, safety guards intended to avoid writes outside recognized kernel-memory regions, structured RMV-MARK/RMV-STATS telemetry, and a DONE file for its downstream orchestrator. Target-specific headers under src/targets/ contain kernel image offsets, structure layouts, memory-layout constants, and transport details for 13 vivo/iQOO kernel identities across Android 14 6.1.x and Android 15 6.6.x. Most use a pselect stack-reuse route; selected Android 14 targets use a multicast setsockopt route. The g24b70dd1cb81 target is explicitly a patched reference build and declares TARGET_IS_PATCHED. Python tooling supports deterministic builds, ELF/symbol safety audits, manifest generation, boot/OTA offset extraction, vulnerability patch-state analysis, log parsing, and ADB-based test-round orchestration. No external TCP/HTTP command-and-control endpoint is present; communications are local filesystem, procfs/sysfs, Android system binaries, and an AF_UNIX socket.
GhostLock is a device-specific Android local-kernel exploit for CVE-2026-43499, described as an rtmutex stack use-after-free in the FUTEX_CMP_REQUEUE_PI rollback path. The repository contains 33 files: build/deployment shell scripts, bilingual operational documentation, exact kernel offset tables, and predominantly C source for an AArch64 static binary named slide_dev. The principal implementation is spread across src/main.c, src/slide.c, src/fops.c, src/pipe.c, src/util.c, and src/target.h; src/qmain.c supplies the executable main routine. The code uses futex PI/requeue activity to leave a dangling rt_mutex_waiter, overlays the waiter through pselect6 stack fd-set copying, and triggers an rt_mutex priority-chain walk whose rb_erase behavior provides a constrained write primitive. The intended short sequence writes a safe page-aligned pointer to SELinux state and replaces the current task's real_cred and cred pointers with init_cred, producing UID 0. It uses perf events to leak KASLR and its own task_struct, while ownprobe identifies a sprayed page without kernel dereferences. KernelSnitch sources provide an alternative futex-hash timing side channel, and cfi.c contains an apparently abandoned/auxiliary CFI-safe ashmem fops-hijack path intended for more general kernel read/write. Following elevation, the binary launches KernelSU's ksud late-load command rather than insmod, enabling a per-boot KernelSU module load despite unexported kernel symbols. The build scripts and Makefile reference src/persist.c, but this source file is not included in the supplied file listing, making the archive incomplete and non-buildable as provided. No exploit framework is used.
This is a 21-file, non-framework repository documenting a device-specific port of the claimed GhostLock (CVE-2026-43499) local kernel exploit against the Huawei MRX-W09 MatePad Pro (Kirin 990, EMUI 11, Linux 4.14.116). It contains one substantive C implementation, enabler/inject_hook.c, a C offset header, a re-root shell script, and extensive Japanese/English research notes. The main exploit source named throughout the documentation (exploit/ghostlock_mrx_e.c) is not included; only exploit/offset_mrx.h is present. Consequently, the local page-cache injection component is directly analyzable, but the claimed full CVE exploitation and root-server implementation are documentation-backed rather than source-verifiable in this snapshot. inject_hook.c opens /dev/mali0, submits Mali kbase ioctls, maps imported user buffers, and patches cached pages corresponding to /system/lib64/libc.so. Its place mode reads shellcode from /data/local/tmp/shellcode.bin and installs it at a supplied libc offset; hook mode overwrites an ARM64 instruction with a branch to that offset; restore mode rewrites the original instruction. tools/reroot.sh automates staging assumptions, hooks libc before running /system/bin/bugreportz, verifies /proc/sys/kernel/perf_event_paranoid equals -1, restores the branch, then launches the missing ghostlock_e --simple payload and creates su-client symlinks. Documentation describes a constrained kernel write primitive, perf-based credential/task leaks, an HKIP bypass using task->pid=0, credential changes, and an abstract UNIX-socket root command service. Numerous hard-coded kernel offsets and link-time addresses make the chain tightly coupled to the cited MRX-W09 firmware/kernel build; failure modes described in the notes include kernel panics and a non-exitable pid-zero shielded task.
This 25-file C/ARM64 repository is an operational local privilege-escalation exploit for CVE-2026-43499, an rtmutex `remove_waiter()` use-after-free reached through futex requeue priority-inheritance operations. It builds an AArch64 Android `preload.so` and embeds a separate PIE su daemon. `src/main.c`, `slide.c`, and `fops.c` orchestrate the futex race, KASLR leak, fake waiter/file-operation routing, and control-flow stage. `kernelsnitch/` provides timing-based futex hash collision logic used to recover kernel `mm_struct` placement; `pipe.c` shapes pipe allocations and converts corruption into verified kernel physical read/write. `root.c` walks task structures and patches credential, capability, seccomp, and SELinux-related fields to obtain root. `preload.c` is executed via an LD_PRELOAD constructor and installs a root su daemon/client, attempts ADB mount-namespace visibility, and writes wallpaper artifacts. Target-specific kernel offsets and layouts are in the Oplus and Vivo target headers; `adaptation-4.19.patch` documents changes from an upstream newer-kernel implementation. The code performs no Internet networking, but creates a local AF_UNIX root service at `/data/local/tmp/temp_su.sock` with mode 0666, making root command execution available to local clients after successful exploitation.
GhostLock is a 35-file Android local-root repository targeting a highly specific Lenovo TB365FC ZUXOS/Android 16 kernel build. Its principal C entry point, src/poc_mcast_root.c, implements CVE-2026-43499 as an rtmutex remove_waiter() use-after-free triggered through multicast networking, futex priority-inheritance manipulation, and related kernel heap/state shaping. It derives or leaks the kernel slide, uses hard-coded GKI symbols and structure offsets, changes SELinux to permissive, then invokes src/pipe.c's DirtyPipe-style forged-pipe technique to patch the current task's credentials directly. This accommodates the target's disabled usermode-helper/modprobe route. The exploit cleans up forged pipe state and synchronization threads after establishing root. Host-side scripts compile static arm64 Android binaries with the NDK, validate the exact kernel/page configuration over ADB, upload the exploit to /data/local/tmp, execute it with a timeout, and require contemporaneous root proof plus a FIFO round trip. The exploit produces unauthenticated root FIFO channels at .rcmd/.rout and a loopback shell on 127.0.0.1:31337. The su/ subtree supplies rootd, a UNIX-socket root-command daemon; a su client; a policy/log management CLI; and a watchdog that restarts rootd. Although rootd has peer-credential checks and policy handling, its absent-policy default grants shell and system users root-command access, consistent with the README warning that the channels are unauthenticated. The ksu/ scripts stage ksud and kernelsu.ko under /data/adb, verify bundled artifact SHA-256 values, invoke ksud late-load, and verify the module through /proc/modules. Optional tooling downloads/installs NeoZygisk and Vector modules and deliberately sets SELinux permissive for Vector. Packaging and CI files build a Windows-oriented bundle containing ADB, PortableGit, binaries, and a batch launcher. This is a functional operational local privilege-escalation/root deployment tool rather than a detection-only script or a standard exploit-framework module.
This 32-file C/ARM64/Python research repository targets CVE-2026-43499 on an Honor YLP-W00 Android tablet running a heavily PGO/LTO-optimized 6.12.38 Android kernel. Its primary local exploit primitive is a three-thread futex priority-inheritance deadlock/requeue sequence (src/futex_trigger.c) intended to leave a stale rt_mutex_waiter on a kernel stack and invoke rt_mutex_adjust_prio_chain/rb_erase through sched_setattr. The repository additionally includes a static ARM64 kernel audit script, KernelSnitch futex-hash timing code for mm_struct/direct-map address disclosure, allocator/SKB page-reclamation logic, an epoll plus IPv6 multicast late-reference race, pipe-buffer page-cache patch logic, and a root-service payload/UNIX su daemon. The intended full chain patches the constructor in /system/lib64/libdumpstateaidl.so, abuses root dumpstatez and bugreportd service execution, disables SELinux using a hard-coded direct-map alias, and exposes root command execution through the dumpstate socket or cathash_su.sock. The code includes explicit verification and retry functionality (--info, --check, --probe-epoll, --probe-pipe, --full) rather than being solely a detector. However, the repository's own README and research timeline state that the actual Honor 6.12.38 target has not been fully exploited: the PI UAF condition and KernelSnitch leak reportedly work, but the epoll/late_refs reclaim race produced zero hits. The documentation also contains conflicting interim conclusions about an adjtimex stack-reclamation vector; docs/CRITICAL_FIX.md states its supposed overlap was an arithmetic error. Further, config/target.h and config/target_honor_ylp_w00.h describe the Honor 6.12.38 target, while src/cmwns_target.h preserves a conflicting 6.12.58 reference profile. Thus, this is substantive operational exploit research with a hard-coded payload, but its documented final privilege-escalation path against the stated Honor target remains unsuccessful/unverified.
GhostLock is a full Android ARM64 local privilege-escalation project targeting CVE-2026-43499, described in src/core/main.c as a futex PI use-after-free. It is not merely a detector: the native C payload implements a multi-stage exploitation chain (W1 SELinux permissive, W2 init_cred credential replacement, W3 seccomp bypass) and attempts KernelSU late loading for a more durable root outcome. The code contains two race/write routes: a select/pselect waiter path used for 6.6/6.12-style waiter layouts and a TCP_ZEROCOPY_RECEIVE plus memfd-hole-punch path for compact 6.1 waiter layouts, with environment controls for route and CPU-core selection. KernelSnitch code assists in locating relevant kernel memory through futex hash collisions. The repository is structured as: native exploit sources under src/core; per-exact-uname kernel offset headers under src/kernels; an Android Jetpack Compose application under app/ that packages and launches the exploit; Gradle/Makefile build integration that compiles the native binary and an offset extractor into JNI-named shared objects; and CI scripts for release artifact creation. The Android app restricts exploitation to supported releases, imports/exports offsets.json, and can parse local boot/xbl images or a user-provided OTA URL. The OTA parser performs HTTP range reads and reconstructs only boot and xbl_config data needed for offset extraction. The listed targets cover many OEM Android 14, 15, and 16 kernels across 6.1, 6.6, and 6.12 branches. No remote victim service is targeted; network use is limited to optional user-supplied OTA retrieval, loopback sockets used as a local exploit primitive, and CI-related downloads/Telegram publication.
GhostLock is a genuine, narrowly scoped local Android kernel privilege-escalation PoC for CVE-2026-43499, a Linux rtmutex/futex priority-inheritance use-after-free. It targets only a Humane AI Pin retail device on the exact 101.000470.45.20 Android 12 profile, Linux 4.14.190-perf November 2024 build, arm64-v8a architecture, and slot _b. It is not a remote/network exploit and does not include ADB credentials, device discovery, persistence, partition writes, or telemetry. The public launcher is the shell wrapper ghostlock, which invokes tools/ghostlock.py for check, build, run, verify, and report workflows. Python profile handling in ghostlock_profile.py strictly binds the profile manifest, minimal symbol list, kernel Image hash, allocator geometry, and payload identity. runner/ghostlock_prod_runner.py orchestrates the guarded ADB-based attempt: it validates device identity and shell/SELinux state, captures a current-boot bugreport, calls runner/ghostlock_bugreport_kaslr.py to derive KASLR only from two agreeing live kernel-log symbol anchors, transfers and hash-checks the payload, atomically claims the single allowed attempt for that boot, and independently verifies root through a fresh shell. The native payload is built by source/Makefile using Android NDK 28.2.13676358. Target-specific code in source/src/targets/humane-aipin-45.20/ implements the exploit chain. KernelSnitch performs futex-hash timing to locate an mm_struct; reclaim_hold.c uses AF_UNIX socket-buffer allocations to reclaim a released order-3 slab page; perf_reclaim_gate.c requires perf tracepoint evidence of exactly one matching page free and allocation for a candidate PFN; fops.c shapes pselect6 result maps into a forged rt_mutex_waiter; and pipe.c supervises each write-route child in a dedicated process group with deadlines and cleanup. The route resolves current-task data, changes real_cred and cred to init_cred, clears SELinux enforcement, and reloads the active policy. After privilege escalation, preload.c atomically installs an embedded su program under /data/local/tmp and starts its daemon. su_daemon.c exposes only a local Unix socket and authorizes peers via SO_PEERCRED for UID 0 or Android shell UID 2000; accepted requests are executed with /system/bin/sh as root. The repository also contains host/unit tests, profile-header generation, release auditing, reproducible-build verification, and redaction tooling. Documentation emphasizes fail-closed target checks, one attempt per boot, crash/hang risk, and removal of private bugreports, addresses, serials, and other sensitive evidence.
This is a 51-file Android/Gradle project, branded GhostLock/Fold 8 Ultra Root, that operationalizes the claimed CVE-2026-43499 late-load vulnerability against narrowly specified Samsung Galaxy Z Fold 8 Ultra SM-F976N (q8q) firmware builds. The primary logic is Kotlin: MainActivity supplies the UI and permission flow; ShizukuController uses the Shizuku Binder API to execute privileged shell commands and write files; Targets selects a firmware-specific payload based on Android build properties; and ExploitRunner stages and launches the chain. The exploit flow clears logcat, starts a filtered GHOSTLOCK logcat process, invokes a shell with LD_PRELOAD set to the staged shared object, then waits up to 60 seconds for root and KernelSU success indicators. It makes at most three attempts and stops if a reboot is inferred from /proc/uptime. RootChecker verifies KernelSU using module-related proc/sys paths or su. BootReceiver and AutoRootService implement optional persistence of the exploit attempt—not persistence of root itself—by rerunning once after boot when Shizuku becomes available. No exploit-controlled HTTP, DNS, IP, TCP, or UDP endpoint is implemented; INTERNET is declared but the presented Kotlin code does not make network requests. Documentation claims six prebuilt payload assets, but no app/src/main/assets files or binaries appear in the provided file structure, so the actual native exploit implementation cannot be assessed from this content.
GhostLock is a device-specific Android local-kernel exploit repository for CVE-2026-43499, a futex priority-inheritance use-after-free in the Linux 5.10 rt_mutex proxy-lock rollback path. The primary intended binary is src/core/exploit.c (referenced by the Makefile and runners), compiled as an Android API 26 AArch64 executable named exploit_guard; its supporting payload implementation is in src/core/payload.c with PFEM10-specific layouts in src/devices/pfem10/pfem10_target.h and fd-set stack mapping in src/core/fdset_map.h. The build deliberately fixes compiler optimization and ABI parameters because exploit geometry depends on them. The chain uses perf-based task_struct leakage, futex collision/requeue manipulation, heap spraying/reclamation, and a forged compact rt_mutex waiter to reach an 8-byte kernel write primitive. The documented primitive writes a chosen value to a chosen target but also writes the target pointer at write_value+0x8. It first can target SELinux enforcement, then targets task->real_cred (0x778) and task->cred (0x780) with the same crafted fake-cred address and performs a repair write to restore damaged credential fields. The crafted credential grants root IDs and full capabilities. The runner includes safeguards and observability for pointer equality, write stamps, lifetime pinning, credential consistency, and post-reboot forensics. Optional elevated execution uses a memfd loader and external KernelSU binaries to load kernelsu.ko. Repository structure includes orchestration scripts (run_bootA.sh, run.sh), an offline rt_mutex state-machine model (model/model.c), C payload and mapping code, Python ELF/kernel/module disassembly utilities, curated vendor-watchdog disassembly artifacts, and extensive device-run evidence. The artifacts analyze OPPO security guard behavior that snapshots credentials and can report/kill a process after suspicious credential changes. The evidence confirms historical uid=0 child execution and KernelSU module loading, but also documents unreliable hit rates, reboot behavior, unvalidated pstore logging, and that the newer private sprayed-page same-value/credential-laundering flow remained untested at the time of the evidence. No network exploitation, callback infrastructure, or remote C2 behavior is present.
This 80-file repository is a multi-target Android local-kernel-exploitation research tree centered on CVE-2026-43499 (“GhostLock”). Its primary complete source project is fusion-s24u: an Android NDK/arm64 C implementation specifically profiled for the Samsung Galaxy S24 Ultra SM-S928U1 DZF2 firmware. The Makefile produces preload shared objects and a PIE root helper. Core files implement futex PI/CMP_REQUEUE_PI race orchestration (main.c and slide_app.c), pipe-cache grooming and a forged pipe-buffer physical read/write primitive (pipe.c), timing-based mm_struct discovery (kernelsnitch headers and util.c), KASLR recovery through tracefs or target fingerprints (slide.c), file-operation/control-flow manipulation (fops.c), and root installation through a crafted kernel usermode-helper work item (root.c). su_daemon.c implements a local UNIX-socket privileged command service and KernelSU-related staging path. The repository also contains a separate Pixel 6 GhostLock adaptation: target headers and extensive adaptation notes for Google Pixel 6-family Android 15/kernel 5.10.214, a Kotlin/Compose Android launcher app, Shizuku and direct wireless-ADB shell execution support, and Windows/Bash verification scripts. The launcher deploys an LD_PRELOAD library to /data/local/tmp and invokes it through /system/bin/true. This branch includes two mm_struct-size variants and diagnostics, but its documentation explicitly says the non-root KASLR leak path is unfinished; saved logs also include devices that were already rooted, so they should not be treated as proof of a reliable unprivileged Pixel compromise. Ancillary top-level C utilities test KernelSU exposure and pipe sizing, while pipe_android61.c/pipe.c.b64 are Linux pipe-source references. The root README describes a separate vivo Y200i investigation that is blocked by stack-frame geometry and is not a functioning exploit. No conventional exploit framework is used. The code has no hard-coded Internet C2 or remote victim endpoint; its observable interfaces are local Android filesystems, tracefs/procfs, and local UNIX sockets.
This is a non-framework, native AArch64 Android local-kernel exploit repository, identified by its Windows build path as targeting CVE-2026-43499 and branded in CI as “GhostLock.” It contains common C sources plus per-firmware target profiles. The build system selects src/targets/<PROJECT>/target.h and optional replacement sources, then cross-compiles preload.so for Android API 35 and embeds a separately compiled su_daemon PIE binary. Loading preload.so invokes its constructor, clears LD_PRELOAD, and runs the exploitation chain. The chain uses futex priority-inheritance/requeue races and pselect (with newer tokay profiles also supporting local TCP and punched shared-memory race routes) to manipulate kernel-side state. It leaks the KASLR slide, uses KernelSnitch timing/collision logic to locate relevant mm_struct/kernel memory, corrupts Ashmem/configfs-related structures and file operations, and establishes pipe-buffer-based arbitrary kernel physical read/write. It then walks the kernel task list for a forked child, patches real/effective credentials, capabilities, SELinux security IDs, and disables SELinux enforcement. The implementation includes offset tables for Ashmem fops, configfs operations, task/credential structures, SLAB/page metadata, pipe structures, and SELinux globals. Post-exploitation code in preload.c and su_daemon.c is overtly operational rather than a benign proof-of-concept: it writes and labels a root su binary, mounts tmpfs at an APEX path, creates a local su client, attempts installation in adbd's mount namespace, and starts an unauthenticated root command/shell daemon at /data/local/tmp/temp_su.sock with mode 0666. It additionally replaces wallpaper files and reloads/restarts wallpaper processing. Source is primarily C with an assembly blob wrapper, supported by Make, Windows CMD/PowerShell, and GitHub Actions build definitions. Target folders enumerate exact Google Android 16/17 Pixel-family build fingerprints; many aliases reuse common frankel or tokay offset/source profiles.
This is a standalone ARM64 C research repository for CVE-2026-43499 (GhostLock), a Linux rtmutex/futex local use-after-free, adapted to the ASUS ROG Phone 5S / Android 13 kernel 5.4.210-qgki-perf. The documented root cause is remove_waiter() clearing state for current rather than waiter->task during a proxy-lock rollback, leaving task_struct->pi_blocked_on pointing to a freed stack-resident rt_mutex_waiter. The intended three-thread W/O/M futex topology uses FUTEX_WAIT_REQUEUE_PI and FUTEX_CMP_REQUEUE_PI to induce EDEADLK and enter that rollback path. The repository reports successful Stage 0 triggering, Stage 1 pselect6-based stack reclamation, and Stage 1.6 kernel-stack address disclosure. Its key technique uses pselect6 with nfds=320 and a zero timeout: core_sys_select copies three 40-byte fd_sets to stack_fds without scheduling, aligning the exception fd-set with the stale waiter at a documented word shift of 10. This gives controlled corruption through waiter+0x27, including tree_entry and only the first 16 bytes of pi_tree_entry. The supplied source set includes a current SELinux/access checker, perf ring-buffer KASLR experiments, a working-looking worker-stack sampler, and numerous legacy C iterations; Bash scripts extract symbols and DWARF-derived structure offsets from a locally built ASUS vmlinux. It is not a completed local privilege-escalation exploit. The documentation concludes that the available pselect layout cannot reach pi_tree_entry.rb_left at +0x28 or waiter->lock at +0x38, both required for proposed write primitives. It also documents unsuccessful KASLR leakage attempts via procfs/sysfs, BPF, system-wide/kworker perf, and perf instruction-pointer samples. Later analysis further states that one presumed rb_erase write path is structurally unreachable because the vulnerable waiter has already been removed from the waiters tree. Consequently, the demonstrated operational impact is kernel corruption and potentially device/process deadlock or crash, not arbitrary write or root access. There are repository consistency issues: README and src/README reference several primary PoC files (for example poc_stage0_trigger.c, poc_stage1_v10.c, poc_stage2b.c, recon_leak3.c, and perf_probe.c) that are absent from the listed archive. include/target.h also contains duplicated and stale KASLR-slide definitions despite later documentation explicitly retracting the purported KASLR leak. These issues limit reproducibility of the claimed Stage 0/Stage 1 chain from this archive alone.
This 25-file repository is a target-specific Android/AArch64 local-kernel privilege-escalation port for Samsung Galaxy S21 SM-G991B (o1s), firmware G991BXXSJHZC2, based on IonStack CVE-2026-43499 research. It is not part of Metasploit, Nuclei, or another recognized exploit framework. The principal implementation is C, accompanied by a Makefile and a Perl generator that creates raw-kernel-image fingerprint tables. The Makefile produces three artifacts: an LD_PRELOAD exploit library, an app-oriented shared object, and a standalone root-helper daemon. `src/main.c` coordinates the futex priority-inheritance race and consumer thread; `exp_stamp.c` and `resbit_route.c` implement alternate kernel-stack planting methods using IPv6 multicast setsockopt and pselect result bitmaps; `slide.c` attempts a KASLR leak through tracefs; `pipe.c`, `fops.c`, and `util.c` implement allocator grooming, KernelSnitch-assisted mm_struct discovery, forged pipe buffers, and intended kernel read/write primitives. `root.c` prepares a call_usermodehelper work-item chain, while `su_daemon.c` implements the local root-command daemon. The `src/targets/o1s-G991BXXSJHZC2/` headers contain hard-coded kernel offsets, structure layouts, direct-map ranges, and KASLR fingerprint data specific to the stated firmware. Despite containing a complete intended exploitation and root-persistence-for-the-boot-session chain, it is explicitly a blocked research port rather than a demonstrated working S21 exploit. `RESEARCH.md` documents that the needed stale `rt_mutex_waiter.lock` field is in an uncovered kernel-stack copy gap; attempted stamp variants fault through a null lock, and the pipe-reclaim gate reports 0/0. The code is consequently capable of dangerous target-local race activity and likely kernel panics, but the repository reports no successful root result for this profile.
This is a 45-file, standalone C exploit repository rather than a Metasploit/Nuclei-style framework module. Its documented and Makefile-built primary payload is src/ghostlock54.c, compiled statically for AArch64 as build/ghostlock54. README.md and VERIFICATION.md identify a validated Sharp AQUOS R6 A101SH/Judau Android 11 S0029 target with Linux 5.4.61-qgki. The payload uses perf-event samples to derive the KASLR text base and runtime SELinux-state address, manipulates futex PI wait/requeue behavior and signal-return/FPSIMD-restored state to obtain a dangling waiter write primitive, disables SELinux, modifies credential identity fields, and launches an interactive root shell directly through the caller's existing ADB terminal. The src/core tree is a more general multi-device exploit implementation: main.c orchestrates runtime offset selection and exploit modes; slide.c performs KASLR leakage; fops.c and util.c build a configfs/ashmem file-operations read/write primitive; pipe_physrw.c upgrades that to arbitrary kernel-memory access with forged pipe_buffer metadata; root.c patches credentials and SELinux; and umh_root.c contains an optional system workqueue/call_usermodehelper execution route. kernelsnitch implements futex-hash timing techniques to infer mm_struct placement. Device offset headers enumerate additional Android device/kernel profiles. tools/ contains perf-based calibration probes, while build/*.txt retains captured measurement output used to calibrate the AQUOS target. No external HTTP/DNS service or remote command-and-control endpoint is present; network-related code is restricted to optional loopback ADB and loopback shell functionality.
GhostLock Sabrina is a substantive standalone local kernel privilege-escalation exploit written primarily in C, not a detection script or a framework module. The Makefile builds a statically linked aarch64 Android binary named ghostlock from src/core/main.c, util.c, and fops.c using the Android NDK. Supporting headers provide the futex-hash timing side channel, target-specific constants, runtime structure offsets, and Sabrina kernel symbol offsets. The exploit targets CVE-2026-43499, described in the repository as a use-after-free in the Linux futex priority-inheritance rollback path. It creates a dangling rt_mutex_waiter reference, leaks KASLR using TID-filtered perf events, leaks the current mm_struct using the bundled KernelSnitch futex-hash collision timing technique, and uses SLUB/io_uring reclaim choreography to place attacker data over a freed kernel page. An AF_UNIX SOCK_SEQPACKET sendmsg stack overlay supplies forged waiter/task/lock fields. A sched_setattr priority sequence triggers the corrupted PI-chain traversal, producing an rb_erase-based arbitrary write. The main payload prepares a self-contained fake credential and user namespace on the reclaimed page, then overwrites task_struct->cred. The documented default --cred path executes /system/bin/sh after successful escalation and leaves a local marker file. The source also contains additional kernel-memory and follow-on exploitation support in fops.c/util.c, including ashmem/configfs-backed read/write helpers, pipe physical read/write helpers, fake file_operations handling, KASLR validation, and optional multi-write plans. Device support is tightly coupled to Chromecast with Google TV (sabrina), Android 14, and kernel 5.15.170-android14-11-gf4a1f03072af; main.c rejects kernels without a matching offsets entry.
This is a device-specific Android local privilege-escalation bootstrap project for a locked-bootloader MEIZU 21 running Flyme 12.6.0.0A, Android 16, and kernel 6.1.25-android14-11-maybe-dirty. It claims to exploit GhostLock/CVE-2026-43499 through the vulnerable compact Linux 6.1 pselect/remove_waiter path. device/offsets.json contains tightly coupled kernel structure and symbol offsets, including credential, seccomp, task, SELinux, init_cred, and selinux_enforcing values; the bootstrap script explicitly rejects other kernel releases. bootstrap.sh is the host entry point. It uses adb to push the GhostLock binary, offsets, helper scripts, and downloaded KernelSU components onto the device; invokes a dry-run validation pass; then starts GhostLock with CPU/routing settings. scripts/root-hook.sh records root proof and detaches root-worker.sh. The worker selects the shell SELinux context, prevents duplicate workers, and continuously executes a queued shell script as root. rootctl.sh writes commands through adb and returns captured output and exit status. The final bootstrap stages install KernelSU Manager and run ksud late-load --kmi android14-6.1 --allow-shell. The archive contains four executable shell scripts, JSON offset data, technical documentation, and a patch to upstream GhostLock that implements GHOSTLOCK_DRY_RUN validation. However, it does not contain the referenced payloads/ghostlock-arm64 file despite README, .gitattributes, and bootstrap.sh all requiring it. Consequently, the supplied archive is an incomplete reproduction package and cannot perform the claimed exploit without acquiring that external prebuilt binary. No standalone GhostLock source is included, so the underlying kernel exploit implementation cannot be independently validated from this repository.
This 51-file repository is an operational, target-specific Android local jailbreak/root kit rather than a network exploit or a detection-only proof of concept. Its primary source tree is under source/exploit/popsicle/, with C implementations for the exploit flow, pselect/FOPS handling, heap/page reclamation, KASLR slide recovery, LD_PRELOAD entrypoint, and an embedded ARM64 su daemon. Supporting KernelSnitch headers implement futex-hash/collision and mm_struct discovery support. The target configuration in source/target-files/popsicle-target.h hard-codes T807D ARM64 kernel addresses, direct-map parameters, task_struct/cred/SELinux offsets, rt_mutex_waiter layout, file_operations offsets, and the expected Android build fingerprint. The chain uses futex priority-inheritance and crafted pselect fd_set state to reach a forged kernel object/file_operations route, gain controlled kernel writes, and apply credentials/SELinux modifications through a root bridge. The preload component embeds and writes a su binary, starts a privileged AF_UNIX daemon at /data/local/tmp/temp_su.sock, and accepts commands from root or Android's shell UID. Shell scripts then late-load KernelSU, enable adb_root and su_compat, adjust ADB-related properties, and forcibly restart adbd. Verification scripts test UID 0, SELinux context, KernelSU module/UAPI state, vital Android services, and display state. Repository orchestration is Windows-centric: run_t807_jailbreak.cmd launches run_t807_jailbreak.ps1, which uses bundled adb to push test payloads to /data/local/tmp, execute the privilege-escalation stages, install/check KernelSU Manager, and collect local logs. rebuild-current-source.ps1 compiles the shared object, helper, and su daemon with Android NDK r29. artifacts/production/ preserves scripts and documented previously validated binary baselines, while test-payload-current-source/ and runtime/ hold current testing and stage wrappers. Documentation states the preserved current source can be rebuilt but is not a byte-for-byte reconstruction of the production binaries. No HTTP, IP, DNS, or remote C2 endpoint is present. The practical attack surface is local physical/USB access with already authorized ADB, and the implementation is tightly coupled to one T807D boot/kernel image; changed boot images, patches, layouts, or offsets are expected to break it or destabilize the device.
ghost-hoock is a standalone aarch64 Android local kernel exploit/PoC, forked from GhostLock and deliberately reduced to one capability: changing SELinux from enforcing to permissive through CVE-2026-43499. It is not a remote exploit and makes no network requests. The build produces a PIE executable named ghost-hoock from src/main.c, src/spray.c, and src/route.c; the repository also includes target-specific headers and bundled KernelSnitch support headers. Execution begins in src/main.c, which verifies the uname release against a single offsets table, logs local SELinux and process-security state, raises resource limits, pins execution to a CPU, and retries the W1 write route up to a configurable number of attempts. src/spray.c implements direct-map alias calculations, Android ashmem discovery, child/memfd allocation helpers, KernelSnitch timing-side-channel wrappers for leaking the process mm_struct location, and slab/SKB heap spraying. src/route.c coordinates waiter, owner, and consumer threads using FUTEX_WAIT_REQUEUE_PI, FUTEX_LOCK_PI, FUTEX_CMP_REQUEUE_PI, and sched_setattr to trigger traversal of attacker-controlled fake PI/rt_mutex structures. Carefully populated pselect fd_sets supply the fake-object values and direct the resulting constrained write. Target configuration is explicitly limited to Samsung Galaxy A17 SM-A175F BZA5 on kernel 6.12.23-android16-5-abA175FXXS5BZD2-4k. include/offsets_bza5.h and include/target.h contain its kernel symbol, task-structure, fake-object-layout, and memory-address constants. The executable's write target is selinux_enforcing, not credentials or a general read/write primitive. Although unused historical offsets for root/configfs-related functionality remain in target headers, the stated and implemented active route excludes credential overwrite, usermode-helper execution, configfs, persistent modification, and shell delivery.
This is a 52-file C/Python repository containing the native, device-specific side of the Root My Galaxy project. It builds AArch64 Android shared-object exploit payloads and a standalone root helper/daemon; it does not contain the Android application that selects, downloads, stages, and invokes them. The Makefile compiles standard and app-domain variants using the Android NDK, selecting one target header at build time. The primary exploit flow is implemented across src/main.c, slide.c/slide_app.c, fops.c, pipe.c, util.c, root.c, and preload.c. The preload constructor supervises repeated child attempts, timing variations, retry safety, and environment-controlled parameters. The root helper and daemon implementation is src/su_daemon.c. The exploit is a local kernel privilege-escalation implementation attributed to CVE-2026-43499. It coordinates FUTEX_LOCK_PI/FUTEX_WAIT_REQUEUE_PI activity with pselect and scheduler manipulation to obtain a controlled kernel-object route. It derives the kernel slide via tracefs where available, or via a physical P0 fingerprint/oracle route in app payloads. It then constructs forged ashmem/configfs file-operation state, reclaims pipe-buffer objects, and installs pipe-based arbitrary physical/kernel read/write. With that primitive it modifies relevant kernel state, including SELinux enforcement, and injects a forged workqueue/user-mode-helper request that starts the root daemon. The daemon exposes privileged command or shell execution only to the configured originating client UID. Target profiles under src/targets contain firmware-specific kernel bases, symbol offsets, task/waiter/file-operation layouts, direct-map details, and 32-entry P0/KASLR fingerprint tables. Profiles cover several Samsung Galaxy S21/S21 FE, S24/S24 FE/S24 Ultra, A15, A56, and S25-series firmware/kernel combinations. Documentation records exact firmware provenance and testing status. The A56 SM-A566E A566EXXSCCZG6 profile is documented as hardware-tested with UID 2000-to-root escalation; several other profiles are static/build verified but explicitly hardware-untested. The kernelsu directory separately contains documentation, a Samsung-specific KernelSU v3.2.5 patch, and Python utilities for recovering/auditing ARM64 module symbol/version compatibility. The patch adds KDP, RKP, and DEFEX-aware behavior and an optional no-live-text-patching mode, allowing matched KernelSU modules to be late-loaded after initial root. support/targets-v2.json and targets-v3.json act as delivery manifests and reference raw.githubusercontent.com-hosted payload and KernelSU artifacts. No network connection is made by the native exploit source itself; network URLs belong to the external support-feed delivery mechanism.
GhostLock is a 34-file, standalone ARM64 Android local-privilege-escalation repository targeting CVE-2026-43499, described as an rtmutex `remove_waiter()` use-after-free reached through futex PI requeue/proxy-lock rollback. Its core C sources are split by stage: `main.c` coordinates futex threads and the stale-waiter trigger; `kernelsnitch/` infers a kernel `mm_struct` address using futex-hash timing/collisions; `slide.c` and `fops.c` prepare fake waiter/fd-set state and hijack ashmem file operations; `pipe.c` turns the access into kernel/physical read-write through forged pipe buffers; and `root.c` patches credentials, capabilities, and SELinux state. `preload.c` is a constructor-based launcher for `LD_PRELOAD` and includes post-exploitation deployment behavior. The build system produces `preload.so` plus an embedded PIE `su_daemon`; the latter exposes root shell and command execution through a UNIX-domain socket. Target offsets and layouts are hardcoded in `src/targets/oplus-4.19.157-perf/target.h`, while auxiliary response files document iterative Redmi K40/alioth builds. The repository contains no network C2 or remote service interaction; its observable endpoints are Android/Linux local filesystem, procfs, sysfs, and UNIX-socket paths. Repository notes also indicate ongoing reliability issues in the PI-tree punch stage on an alioth/K40 adaptation, despite recent changes to reject invalid memory-leak candidates and disable an incorrect linear-map delta search.
This 11-file repository is an operational, device-specific port and automation kit for GhostLock, targeting CVE-2026-43499 in the Android/Linux futex PI requeue path. It does not include the runnable native exploit, KernelSU daemon, APK, or offsets JSON; those are stated to be release assets. The tracked source consists of two PowerShell scripts and `src/ghostlock-mcast.patch`, a patch intended for upstream `YuKongA/ghostlock-app` at commit 50d2b72. Five extensive Chinese-language Markdown documents record reverse engineering, test results, target offsets, transport selection, failure analysis, and operating guidance. The patch adds an MCAST route selected with `GHOSTLOCK_ROUTE=mcast` or `GHOSTLOCK_MCAST_ROUTE=1`. It invokes IPv4 `MCAST_JOIN_SOURCE_GROUP` with a 0x108-byte option buffer. On the documented target kernel, this causes `do_ip_setsockopt` to copy attacker-controlled data over a stale stack-resident `rt_mutex_waiter` left referenced by `task->pi_blocked_on` after FUTEX_WAIT_REQUEUE_PI. A consumer thread invokes sched_setattr to enter `rt_mutex_adjust_prio_chain`; manipulated RB-tree waiter data turns rb_erase relinking into controlled kernel writes. The stated stages disable SELinux, redirect a child credential to init_cred, and clear seccomp, after which the root script late-loads KernelSU. `run-at-lockscreen.ps1` optionally reboots the connected ADB device, waits at the lock screen, validates/pushes release assets to `/data/local/tmp`, starts ghostlock in the background, and detects success by checking `/proc/modules` for KernelSU. `retry-if-needed.ps1` is a general retry loop that waits for boot completion and an uptime greater than 240 seconds. Both are designed around instability: unsuccessful heap/page-reclaim races can cause a kernel panic and automatic reboot. The repository claims approximately 25-30% success per ordinary attempt and improved reliability while the target stays locked. Root is explicitly temporary because KernelSU is late-loaded and does not survive reboot.
This is a native ARM64 Android local-kernel privilege-escalation repository targeting CVE-2026-43499. It builds an `LD_PRELOAD` shared library (`build/<project>/bin/preload.so`) rather than a network-facing exploit. Its preload constructor clears `LD_PRELOAD` and invokes the exploit whenever the library is loaded into a local process. The primary chain uses futex priority-inheritance/requeue operations, controlled `pselect` fd-set stack data, scheduler timing, heap grooming, and KernelSnitch timing/collision techniques to leak kernel state and defeat KASLR. It corrupts/redirects file-operation structures associated with Android ashmem/configfs handling, then establishes pipe-buffer-based physical/kernel-memory read and write primitives. `root.c` walks kernel task structures and modifies credential fields, capabilities, SELinux credentials/SIDs, seccomp-related state, and optionally SELinux enforcement. This produces root in both a child and, by default, the invoking process. Post-exploitation behavior is significant: `src/ksud_blob.S` embeds a KernelSU userspace binary, while `src/preload.c` writes it beneath `/data/local/tmp`, attempts a `chcon`, and launches it in KernelSU `late-load` mode with `--allow-shell` enabled by default. Environment variables can alter the destination, log path, package name, staging mode, SELinux behavior, and whether the current process is credential-patched. `src/su_daemon.c` additionally contains a separate UNIX-domain root-shell daemon/client implementation, but the supplied Makefile's main artifact embeds KernelSU rather than compiling that daemon. Repository layout consists of common C sources (`main.c`, `slide.c`, `fops.c`, `pipe.c`, `root.c`, `preload.c`), KernelSnitch helpers, assembly blob wrappers, and a large `src/targets/` hierarchy. Target directories hold per-device/per-build kernel symbol offsets and structure layouts for Google Pixel codenames, ASUS I005/ROG Phone 5S, Xiaomi duchamp, and others. The Makefile selects target-specific overrides when present and otherwise uses common sources. The README identifies `rodin` as the default and verified profile, while most others are reference/adaptation configurations. The included ASUS 5.4 QGKI report explicitly says its final pselect overwrite route failed due to incompatible stack layout, indicating target success is highly layout- and build-dependent. No external HTTP, DNS, or remote command-and-control endpoint is present.
This 52-file Android project is an operational local privilege-escalation wrapper for the claimed CVE-2026-43499 against selected Samsung Galaxy S26/S26+/S26 Ultra Android 16 GKI 6.12 builds. It contains a Kotlin Android application, a vendored ARM64 C exploit under exploit/src, NDK/Make/CMake build definitions, and an asset-staging script. The app uses Shizuku when available to run as the Android shell user, stages native payloads in /data/local/tmp, invokes env LD_PRELOAD=... sh, retries the probabilistic race, verifies uid=0, and offers a one-shot root command interface. The native chain is substantive exploit code rather than a detector: it matches supported builds to hardcoded kernel offsets, leaks the KASLR slide via tracefs sched_blocked_reason raw events, uses KernelSnitch/futex timing techniques and page spraying, drives a futex PI/pselect route to establish a forged uinput/uhid attribute carrier, and obtains kernel read/write capabilities. It then changes the SELinux enforcement state and forges a workqueue usermode-helper request that starts a root su daemon. That daemon listens on /data/local/tmp/temp_su.sock for commands and attempts to install/activate KernelSU through a private mount namespace and bind mount over /system/bin/logcat. The implementation has a boot-claim guard due to instability risks, but supports a BOOT_FORCE override. There is no exploit network C2, remote target, or data-exfiltration logic evident. INTERNET permission is documented as being for local socket handling; exploit-relevant communications are local UNIX-domain sockets and Android/Shizuku IPC. The project is not a recognized Metasploit/Nuclei-style module and uses hardcoded kernel-line offsets, so its payload and target adaptation are limited to the enumerated firmware lines.
This is a 28-file, standalone Android kernel-exploitation research repository targeting a tightly profiled Amazon Fire 7 9th-gen (mustang) device. Its operational path is run.sh, which optionally builds poc/stage3.c and poc/su.c, transfers them through ADB, then retries the exploit across device reboots. The primary CVE-2022-38181 implementation uses /dev/mali0 kbase ioctl operations to create and evict a JIT region, reclaims the resulting freed kmalloc-96 object with controlled inotify event-name allocations, and turns kbase_jit_free list unlink writes into a redirect of an IPv4 LOCAL_OUT netfilter hook. The forged hook calls commit_creds(init_cred), after which post-exploitation code disables SELinux enforcement and installs a setuid helper at /data/metrics/su. Hard-coded kernel addresses make it specific to the documented 4.9.117 build, and the heap reclaim is acknowledged as probabilistic. The poc directory also contains earlier CVE-2022-38181 lifecycle/race/UAF validation stages plus two experimental GhostLock CVE-2026-43499 futex PI/rtmutex stack-UAF attempts. The GhostLock work is described as parked and is not the runner's main route. rootcmd.sh is a post-root cleanup script targeting Amazon Venezia package processes and data. The tools directory contains ELF/kernel-disassembly and symbol/address-resolution helpers, inotify heap-spray measurement programs, and MediaTek preloader HID utilities. The latter identify USB 1949:20ff, probe the standard MTK byte-pair handshake, and implement guarded read32/write32 protocol operations that could potentially enable raw eMMC research, but are separate from the main local kbase exploit.
This 16-file repository is primarily a Chinese research notebook and automation toolkit for a claimed CVE-2026-43499 local Android kernel privilege escalation against one Honor WIN RT kernel build. It does not contain the actual exploit binary, native source, symbol table, or upstream Python driver; instead it describes and orchestrates an externally obtained LD_PRELOAD payload from Linuxoid-cn/CVE-2026-43499-Poc-Analysis. The core documented technique is a futex priority-inheritance race reached through an rt_sigreturn stack-copy carrier, producing constrained write-what-where behavior and a kernel-memory read via the random UUID interface. The intended chain disables SELinux enforcement, changes current task credential pointers to init_cred, and deploys a temporary su daemon. Six shell entry points comprise the executable portion: auto_root.sh retries a two-stage ADB workflow and detects reboot/panic failures; wireless_autoroot.sh discovers USB or mDNS-advertised wireless ADB targets; onphone_root.sh runs the same chain through Shizuku/rish without a computer; rt and rts invoke the resulting temporary root, with rts attempting a shell-domain transition for Binder access; and rtdiag.sh inventories root capabilities and warns about required resident processes. The docs cover target feasibility, carrier selection, instability analysis, Shizuku execution, optional KernelSU late-load, failed alternatives, and host/device environment issues. A notable operational limitation is that the forged waiter reportedly remains referenced in real futex PI structures. The repository says this residual state can cause rt_mutex_adjust_prio_chain crashes and forced reboots when scheduling, priority, network, USB, wireless-debugging, or KernelSU module-loading activity occurs. Accordingly, it retains child processes and spray pages, warns not to kill them, and characterizes the resulting root access as short-lived and hazardous rather than persistent.
This 23-file repository is an operational, device-specific Android local privilege-escalation exploit claimed to target CVE-2026-43499. It is a streamlined RootMyVivo-oriented fork for the iQOO Neo 11 (PD2520), firmware PD2520-BP2A.250605.031.A3, with offsets tied to a particular Android 15 / Linux 6.6.89 arm64 kernel. It contains C sources, headers, one ARM64 assembly embed stub, a Makefile, and a Windows NDK build script. The build produces preload.so plus an AArch64 PIE su daemon embedded into that shared library. The LD_PRELOAD constructor in src/preload.c runs the exploit repeatedly in fresh child processes, unsets LD_PRELOAD, and records final state in /data/local/tmp/rmv/DONE. The core path uses futex priority-inheritance requeue behavior to create a dangling rt_mutex waiter reference, then abuses pselect fd-set stack copying to place forged waiter, task, lock, and file-operation data in kernel-controlled positions. slide.c uses this route to disclose a kernel text address and derive the KASLR slide. fops.c then corrupts ashmem-related file operations to establish a privileged file descriptor. pipe.c shapes kmalloc pipe-object allocations and forges pipe buffers to implement physical kernel memory read/write primitives. The target-specific root.c walks task structures, finds the exploit child, overwrites credential UID/GID/capability and SELinux fields, and attempts to set SELinux enforcing to 0. It then deploys a local root su service: the embedded binary is atomically installed at /data/local/tmp/su, run as a daemon, and accepts clients over /data/local/tmp/temp_su.sock. This repository deliberately contains no TCP listener, C2 endpoint, or outbound network behavior; README comments explicitly state that an upstream IO daemon on TCP port 39555 was removed. Post-exploitation code in posture.c performs best-effort kernel-state modification after root: it disables panic-on-oops/warn, exposes kernel pointers and other sysctls, can manipulate SELinux AVC behavior, and can optionally modify an Android vendor commit_creds tracepoint. safety.c adds CPU-idle quiescing and kernel-value sanity checks to reduce crashes caused by timing-sensitive heap reclaim and erroneous kernel writes. The exploit is not merely a detector or README and includes a concrete root payload, but customization is constrained by its tightly hardcoded device/kernel offsets rather than a general-purpose exploitation framework.
This is a build-specific, operational arm64 Android kernel local-privilege-escalation port of GhostLock for CVE-2026-43499. The main native payload is compiled from exploit/src/ into an LD_PRELOAD shared library for the exact NVIDIA Shield TV Pro 2019 mdarcy Android 11 / Linux 4.9.141-tegra 9.2.4 build. It uses futex PI race orchestration, signal or multicast stack stamping, slab and skb reclamation, a forged ashmem file_operations table, and legacy configfs handlers to establish kernel memory access. It then traverses the task list and modifies the live adbd credential object rather than installing a shell or altering verified partitions. The source contains both configfs-based task/credential patching and an inherited pipe-buffer physical read/write implementation, though documentation states the latter is not used for the validated Shield route. The repository includes exact target offsets in exploit/targets/shield-mdarcy-9.2.4/target.h, plus an older OPPO PCKM00 reference target and provenance report. analysis/ contains Python, C, and shell tooling to recover kallsyms, kernel offsets, layouts, and target headers from firmware images. build/ provides an NDK container build definition. Persistence is implemented as an ordinary userdata APK under persistence/: a non-exported BOOT_COMPLETED receiver launches a temporary foreground service, which starts a native runner. The runner refuses privileged execution, validates the device fingerprint, kernel release, and payload SHA-256, stores pre-trigger state, limits attempts to one per boot, and applies a 15-minute cooldown before setting the exploit environment and executing /system/bin/true with LD_PRELOAD. The APK uses package com.cyberbalsa.ghostlockboot and embeds both the runner and exploit library. PowerShell scripts install, arm, verify, and remove this APK through authorized ADB. watchdog/ supplies an optional rootless Podman/systemd user service for an authorized external ADB host. It validates the same target identity and payload hash, checks whether adbd is already root, tracks boot IDs and retry limits, pushes/runs the payload only when needed, and retains state in a mounted host directory. No hard-coded victim IP address or domain is present; network operation uses a user-provided ADB host:port template.
This is a substantial, target-specific AArch64 Android local privilege-escalation repository claiming CVE-2026-43499. The Makefile builds `preload.so` with Android NDK API 35 and embeds a separate PIE `su_daemon` plus a wallpaper asset. Loading the shared object triggers its constructor, clears `LD_PRELOAD`, and runs the exploit automatically. The default project is `blazer-CP2A.260605.012`; target directories select hard-coded kernel offsets and, for newer Pixel targets, replace core source files with a more elaborate tokay implementation. The exploitation chain coordinates FUTEX_LOCK_PI, FUTEX_WAIT_REQUEUE_PI, and FUTEX_CMP_REQUEUE_PI activity across multiple threads, manipulates scheduling timing, and abuses crafted pselect fd sets (or target-specific local TCP/zerocopy routes) to establish a controlled kernel state. It uses KernelSnitch-style futex hash timing and controlled mm_struct allocation to infer kernel/direct-map information, leaks the KASLR kernel text base, performs slab/pipe-buffer spraying and reclamation, corrupts/uses ashmem/configfs-related file operations, then validates arbitrary kernel physical/direct-map reads and writes. Hard-coded offsets cover ashmem fops, configfs handlers, task/cred structures, SELinux state, kmalloc caches, and pipe-buffer structures. After obtaining kernel read/write capability, `root.c` walks the kernel task list to locate its child process and patches its credential objects: UID/GID identity values, capabilities, SELinux SID/security data, and related restrictions. It writes the SELinux-enforcing flag to permissive and has the child call `setgid(0)` and `setuid(0)`. Post-exploitation code mounts tmpfs at `/apex/com.android.virt/bin`, deploys an embedded root su daemon, optionally makes it visible in adbd's mount namespace, and creates a mode-0666 local Unix socket at `/data/local/tmp/temp_su.sock`. Any local process able to access that socket can request a root shell or execute a supplied shell command. The payload also writes embedded wallpaper content into system wallpaper paths and causes/schedules framework reload behavior. Repository layout: common baseline code is in `src/`; `kernelsnitch/` supplies futex hash/timing primitives; `main.c`, `slide.c`, `fops.c`, `pipe.c`, `util.c`, and `root.c` implement the exploit stages; `preload.c` implements deployment and persistence-like post-exploitation behavior; `su_daemon.c` is the root command service; and `targets/` contains build fingerprints, kernel offsets, and target-specific source overrides. Supported fingerprints include multiple Google Pixel Android 16/17 builds, a Samsung A37 Android 14 build, and a documented Pixel 6/oriole environment. No external network, DNS, HTTP, or C2 endpoint is present; networking is limited to a dynamically allocated loopback TCP pair used by certain local exploit variants.
This seven-file repository is a firmware-specific local privilege-escalation exploit for Toshiba/Amazon hazel Fire TV devices. Its primary C entry point, hazel_root.c, targets CVE-2026-43499 on the PS7716.5665N Fire OS build and a 32-bit Linux 4.9.113 kernel. It coordinates futex PI locking/requeueing threads, scheduler-triggered stack stamping, socket/object spraying, and forged ashmem file operations. hazel_reclaim.h supplies the target-specific futex-key collision/address-leak logic and mm_struct SLUB cross-cache reclaim via AF_UNIX allocations. The exploit uses hardcoded kernel addresses and offsets to establish kernel read/write access, locate the current task, and patch credentials to root. It then maintains the required reclaimed objects and runs a local root command daemon at @hazel_root. Four Android shell scripts are post-exploitation utilities: disabling OTA packages, disabling/restoring selected Amazon enforcement/ACR/metrics packages, changing the HOME launcher to Projectivy, and restoring the stock Amazon launcher. No external C2, remote URL, or hardcoded IP target is present; network ADB is only documented as an operator deployment option.
This 17-file Android/Gradle project builds a GUI launcher rather than the native CVE exploit itself. MainActivity requests Shizuku authorization, lets the user select an arbitrary .so through Android's document picker, and binds a Shizuku UserService. CommandService runs shell commands and writes caller-provided bytes with the service's shell/root context. The launcher writes the selected file to /data/local/tmp/preload.so, changes its mode to 755, and launches /system/bin/sh with LD_PRELOAD set, relying on the library constructor to execute payload code. It streams stdout/stderr back to the GUI via AIDL callbacks and displays/copies logs. README.md and EXPLOIT_CN.md describe a claimed CVE-2026-43499 rt_mutex stack use-after-free chain against a specific Honor Android kernel, including arbitrary kernel read/write, KASLR bypass, credential replacement, SELinux disablement, and su installation. Those exploit stages, hard-coded offsets, and preload.so are absent from the repository, so the claim cannot be independently validated from this source and successful exploitation depends entirely on an external payload. The remaining files are Android manifest/resources, Gradle build configuration, a GitHub Actions APK-build/release workflow, and GPLv3 license.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
244 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An important-severity local vulnerability affecting an unspecified AlmaLinux 9.6 package or component. It requires local access and low privileges, needs no user interaction, and can result in high impact to confidentiality, integrity, and availability.
An important-severity locally exploitable vulnerability affecting Rocky Linux 9.6 systems covered by the referenced CLSA advisory. It requires low privileges and no user interaction, and can result in high impact to confidentiality, integrity, and availability.
A vulnerability addressed by the referenced CentOS Stream 8 TuxCare security update; no technical details are provided.
A vulnerability addressed in Huawei EulerOS UVP 2.10.1 kernel-related packages.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.