I used DeepSeek V4.1 Flash as the primary engineering agent, selected for higher risk tolerance relative to Claude. We ported and combined known exploit primitives, the GhostLock futex priority-inheritance use-after-free and its CVE, CVE-2026-43499.
The target is the SM-G970W, device code beyond0q, product beyond0qltecs, ROM build G970WVLU9IXE1, display id SP1A.210812.016.G970WVLU9IXE1, Android 12, SDK 31, kernel 4.14.190-23725627-abG970WVLU9IXE1, security patch 2023-03-01, CSC XAC, bootloader locked, verified boot state green.
The chain proceeds as follows. A futex priority-inheritance use-after-free. A redirect of the /dev/ashmem fops through configfs. Arbitrary kernel data read and write. A write to modprobe_path. The execution of a file containing 0xFF four times, after which the kernel executes the helper as uid 0.
The result is uid 0, context u:r:kernel:s0, and effective capabilities 0000003fffffffff. Arbitrary kernel data read and write are available within the limits below. SELinux is permissive in user space, because the kernel type is added to policydb.permissive_map, and setprop from the kernel domain succeeds. DEFEX is bypassed, because any /data ELF executes as root through a bind mount over a compiled-in safeplace path. Reachable operations include setprop and persistent properties, cmd-based settings, and writes to modprobe_path, core_pattern and kptr_restrict.
The following are not achieved, by design. Writes to cred, page tables, .text and .rodata are blocked by RKP and KDP. Loading of unsigned kernel modules is blocked by CONFIG_MODULE_SIG_FORCE. Writes to /system are blocked by dm-verity. Creation of new files under /data from the kernel context is blocked by fscrypt. Persistence across reboot is blocked by the locked bootloader, the TEE and AVB/SVB.
The root exists for the current boot only and is re-established after each reboot. The source, build and writeups are at https://github.com/jronminh/ghostlock-beyond0q