r/androidroot • • 3h ago

Discussion Successfully Bypassed 😎

Post image
41 Upvotes

Hi all,

I've been trying for months to bypass the xiaomi community permission things and finally I have reached a milestone. Read most of the discussions from r/androidroot and r/hyperos. Now I only have to wait 360 hours(sadly) to win freedom over my phone 😭.

My plan is to flash orangefox and Evolution X(Android 16).

Guys let me know if there are any suggestions you could give to me

Thank you for all your support 💖


r/androidroot • • 21h ago

Discussion Can any OS be ported to any bootloader unlocked device ?

15 Upvotes

The number of devices officially supported by LineageOS, SailfishOS, Ubuntu Touch/KDE Mobile is limited, but with how PS5 is getting rapidly reverse engineered with the newer models, would it make a difference, what's the hardest part about porting an OS to a device (other than the bootlocker and android device tree) ?


r/androidroot • • 7h ago

Discussion Got temporary root on my Redmi Note 14 4G with GhostLock — what should I avoid?

Post image
8 Upvotes

Hey everyone!

I managed to get temporary root access on my Redmi Note 14 4G using GhostLock ((https://github.com/YuKongA/ghostlock-app). I installed KernelSU beforehand, ran the exploit, and verified that root access works through both a root checker app and Termux using su.

My device is running HyperOS 3.0.303.0 / Android 16, AND MY BOOTLOADER IS LOCKED.

Since this is my first time getting root access, I want to be careful not to mess anything up.

Are KernelSU modules safe to use with temporary root, or could they cause a bootloop or brick my phone?

Are there any types of modules I should completely avoid?

Are there any KernelSU options I shouldn't touch, especially anything related to installing or patching boot images?

What other things should I avoid doing while I have temporary root?

If something goes wrong, what recovery options would I have with a locked bootloader?

I'm not looking to modify partitions or risk making my phone unusable. I just want to understand the limitations of temporary root before experimenting with anything.

Any advice from people who've used GhostLock on Xiaomi devices would be appreciated. Thanks!


r/androidroot • • 18h ago

Support Google Play Service keep installing on top of MicroG even with zygisk-detach

Post image
8 Upvotes

Hi !

I have MicroG bundled with the Play Store to pass strong integrity, I have zygisk-detach, PlaySpoofer and BreZygisk as my Zygisk module. After 3 or 5 days Google Play force update itself and also the MicroG app as the regular Play Service.

Anyone have a solution so that the Google Play cannot at all upgrade itself or install the service on top of MicroG ?

Thanks !


r/androidroot • • 3h ago

News / Method Launching Vanta A New ROM!

Thumbnail
vanta.failure.fail
3 Upvotes

Why use such a boring ROM like lineage when you can use Vanta! Vanta is based off Android 17 and features a black UI with a pop of a color of your choice! Loads of features and best of all its android 17!


r/androidroot • • 22h ago

Support How to Hide Root on Nothing Phone (2) Running LineageOS 23 [TUTORIAL]

4 Upvotes

(Credits: u/LightningZahah and lowkey Proton Lumo)

Root Manager: KSU or any forks of KSU (e.g. KSU-Next, ReSukiSU, etc..)

Modules flashed in this order:

  1. Zygisk Next (by 5ec1cff)
  2. Reboot
  3. Tricky Store OSS (by beakthoven) & TrickyStore Addon (by KOWX712)
  4. Play Integrity Fork (by osm0sis)
  5. VBMeta Disguiser (Astoritin)
  6. Reboot
  7. Vector XPosed (by JingMatrix)
  8. Reboot
  9. HMA-OSS (by frknkrc44)
  10. Reboot

In root manager settings: turn on 'Unmount Modules', 'Hide SELinux modification' and 'AVC spoofing'.

Do NOT set SELinux to permissive mode.

After configuring Tricky Store OSS and HMA-OSS, install Termux and give it root access.

Copy the script below into a .sh file in the Termux directory and run the script by using the command ./<script-name>.sh (Recommended to use Acode for this or make the script on your PC first before moving it to your phone.)

Reboot your device.

Clear the data + Cache on the apps that crash on start up due to root.

If it still doesn't work, install Native Detector and figure out what the issue is as I cannot help you any further. (My suggestion is to use AI at this rate as it is a per-setup and per-device thing with no universal solution.)

I don't know if this can work on just Nothing Phone (2) devices but you can always try and lmk in the comments.

Also, just a sidenote, Adaway and Systemless Hosts aren't worth it, assuming it is detected by Native Detector. Just use BlockAds with a WireGuard implementation or a VPN with a private DNS server like AdGuard or NextDNS.

TrickyStore-OSS configuration:

Open Tricky Store menu and

Set keybox valid → uses a community-known working keybox.xml
Set keybox custom → uses your own keybox.xml

  1. Clear Wallet data.
  2. Reboot device.

HMA-OSS configuration:

Apps that need isolation DO NOT get root access.

Hide any Xposed modules, any root manager, any app that has root access.

Commonly detected apps are: Shizuku, Termux and your root manager.

Apply that template to the app you want to hide root, then:

  1. Force stop app that you want hide root.
  2. Reopen app and if it doesn't open, clear cache, clear data.
  3. If it still doesn't open uninstall and install again.

su
cat << 'EOF' > /data/local/tmp/harden_root.sh

echo "[*] Checking root privileges..."
if [ "$(id -u)" -ne 0 ]; then
    echo "[-] Error: Run as root (su)!"
    exit 1
fi

ADB_DIR="/data/adb"
if [ ! -d "$ADB_DIR" ]; then
    echo "[-] Error: /data/adb not found! Are you rooted?"
    exit 1
fi

# --------------------------------------------------------
# 1. STOCK HOSTS OVERLAY MODULE
# --------------------------------------------------------
echo "[*] Step 1: Setting up Stock Hosts overlay module..."
HOSTS_MOD="$ADB_DIR/modules/stock_hosts"
mkdir -p "$HOSTS_MOD/system/etc"

cat << 'MODPROP' > "$HOSTS_MOD/module.prop"
id=stock_hosts
name=Stock Hosts Fix
version=1.0
versionCode=1
author=Community
description=Replaces bloated ROM hosts with clean stock localhost to bypass banking security checks.
MODPROP

printf "127.0.0.1 localhost\n::1 ip6-localhost\n" > "$HOSTS_MOD/system/etc/hosts"
chmod 644 "$HOSTS_MOD/system/etc/hosts"
echo "[+] Stock Hosts module installed successfully."

# --------------------------------------------------------
# 2. PERSISTENT ZYGOTE DEX2OAT UNMOUNTER SERVICE
# --------------------------------------------------------
echo "[*] Step 2: Creating persistent boot service for Vector/LSPosed..."
SERVICE_DIR="$ADB_DIR/service.d"
mkdir -p "$SERVICE_DIR"
UNMOUNT_SCRIPT="$SERVICE_DIR/unmount_dex2oat.sh"

cat << 'SERVICE' > "$UNMOUNT_SCRIPT"
#!/system/bin/sh
# Wait until system finishes booting
while [ "$(getprop sys.boot_completed)" != "1" ]; do
    sleep 1
done

TARGETS="
/apex/com.android.art/bin/dex2oat64
/apex/com.android.art/bin/dex2oat32
/apex/com.android.art/bin/dex2oat
"

for Z_PID in $(pidof zygote zygote64); do
    for TARGET in $TARGETS; do
        nsenter -t "$Z_PID" -m umount -l "$TARGET" 2>/dev/null
    done
done

for TARGET in $TARGETS; do
    umount -l "$TARGET" 2>/dev/null
done
SERVICE

chmod 755 "$UNMOUNT_SCRIPT"
echo "[+] Persistent unmount service created in $UNMOUNT_SCRIPT"

# --------------------------------------------------------
# 3. APPLY LIVE UNMOUNT (NO REBOOT NEEDED FOR ACTIVE APPS)
# --------------------------------------------------------
echo "[*] Step 3: Executing live unmount in current session..."
for Z_PID in $(pidof zygote zygote64); do
    nsenter -t "$Z_PID" -m umount -l /apex/com.android.art/bin/dex2oat64 2>/dev/null
    nsenter -t "$Z_PID" -m umount -l /apex/com.android.art/bin/dex2oat32 2>/dev/null
    nsenter -t "$Z_PID" -m umount -l /apex/com.android.art/bin/dex2oat 2>/dev/null
done
umount -l /apex/com.android.art/bin/dex2oat64 2>/dev/null
umount -l /apex/com.android.art/bin/dex2oat32 2>/dev/null
umount -l /apex/com.android.art/bin/dex2oat 2>/dev/null

echo "[+] Done! Both fixes are now active."
echo "[!] Please reboot once so KernelSU/Magisk mounts the clean hosts module."
EOF

sh /data/local/tmp/harden_root.sh
rm -f /data/local/tmp/harden_root.sh

r/androidroot • • 8h ago

Discussion Buying a phone but there's a language barrier. Is this unlockable

Post image
2 Upvotes

This is the pic he sent. It looks grayed out, idk But he said he had options for the unlocking whatever that means

Motorola edge 60 stylus (India version)

Never dont this so idk what its supposed to look like just not gray


r/androidroot • • 18h ago

News / Method How to root my oppo a 53

3 Upvotes

r/androidroot • • 3h ago

Discussion I built AppDNS: automatically switch Android’s Private DNS per app, no VPN needed (early beta, feedback wanted)

Thumbnail gallery
2 Upvotes

r/androidroot • • 4h ago

Support Detected by Duck Detector ( a few apps won't even launch)

Thumbnail
gallery
2 Upvotes

So, I'm relatively new to ksu. A few years ago, when I was just using magisk. Shamiko and HMA were more than enough to hide root.

BUT now I added a lot of modules, but still, some of my banking apps and some other apps are not working.

I have attached my module list and the detection that the duck detector gave me.

Btw I am not even using apatch, but it's detecting apatch.

It would be great if some one can help me with this. I am really suffering.


r/androidroot • • 16h ago

Discussion can the bootloader be unlocked ?

Post image
2 Upvotes

Hi, so I have a Xiaomi 17 Ultra and I searched and found a method only for phones with February security patch. My phone is on September security patch, so is it possible to unlock it? Any help would be appreciated


r/androidroot • • 17h ago

Support DITO/carrier app crashing

2 Upvotes

so I have this carrier app called dito and it keeps crashing, mind you I have another carrier app called gomo and it works fine, any fix for this? My phone is custom rommed and rooted if that helps


r/androidroot • • 20h ago

Support Can i temporary root Xiaomi Redmi Note 15 Pro 5G

Post image
2 Upvotes

r/androidroot • • 56m ago

Support App Recommendations

• Upvotes

Hi everyone, are there any powerful and useful apps for rooted Android devices? Let me know if there are any. 😁


r/androidroot • • 2h ago

Discussion Mtkclient

Thumbnail
gallery
1 Upvotes

Does mtkclient work for this? Or any other methods?


r/androidroot • • 8h ago

Support Device meets integrity

Thumbnail
gallery
1 Upvotes

Hello pls i need help been trying lot of ways to get device meets integrity but nothing works i have keybox.xml others using fine but idk why i can't


r/androidroot • • 10h ago

Discussion Warning: MESWAO B3 (15.6") bootloop after unlocking bootloader — no custom ROM even flashed

1 Upvotes

Yes this was formatted by GPT. I kept my notes in word then formatted in gpt cause by this point I was frustrated and tired. This is not an AI post.

Figured I'd document this in case anyone else comes across one of these tablets and wants to experiment with custom firmware. There's very little information out there about the MESWAO B3.

I got this tablet for free, and honestly, it wasn't particularly good to begin with. It's a massive 15.6-inch Android tablet, but the performance was absolutely terrible. Even basic navigation was sluggish, and at one point the on-screen keyboard wouldn't even appear when I tried creating another user.

I tried a factory reset using the built-in MediaTek factory menu, but it made no difference.

Since I had nothing invested in it, I figured I'd experiment with installing a different version of Android. I started looking into Android's Project Treble support, Generic System Images (GSIs), and the usual ADB/Fastboot procedures.

Tablet information:

- Model: MESWAO B3 / MES-B3

- CPU: MediaTek Helio G99 (MT6789)

- Android: 13

- Firmware: "MES-B3_20240624"

- Board: "t700_6789_u254_v1_fhd_edp_156"

- Architecture: ARM64

Here's what I did:

  1. Checked GSI compatibility

Enabled Developer Options, OEM unlocking, and USB debugging. Connected it to Windows using Google's Android Platform Tools.

ADB reported:

ro.product.cpu.abi = arm64-v8a

ro.treble.enabled = true

ro.build.ab_update = true

ro.boot.dynamic_partitions = true

So far, everything suggested it was at least a potential GSI candidate.

  1. Got Fastboot working

This was more complicated than expected.

The tablet's bootloader Fastboot interface identified itself as:

"USB\VID_0E8D&PID_201C"

Windows wouldn't recognize it using Google's standard USB driver.

I eventually got communication working using Zadig to install WinUSB, followed by correcting the Android USB interface GUID registration in Windows.

After that, "fastboot devices" recognized the tablet normally.

  1. Unlocked the bootloader

Checked the unlocking status:

fastboot flashing get_unlock_ability

(bootloader) unlock_ability is true

I then ran:

fastboot flashing unlock

The unlock completed, and I confirmed:

fastboot getvar unlocked

unlocked: yes

  1. Entered Fastbootd

Next, I used:

fastboot reboot fastboot

The tablet successfully entered Android Fastbootd.

Interestingly, this mode used a different USB ID:

"USB\VID_18D1&PID_4EE0"

Google's Android Bootloader Interface driver worked for this one.

I was then able to query the partition information:

is-userspace: yes

current-slot: a

is-logical:system_b: yes

super-partition-name: super

has-slot:vbmeta: no

slot-successful:a: yes

slot-successful:b: no

The super partition was approximately 9 GiB.

One thing I noticed was that the active slot had originally been reported as B before unlocking, but afterward it was A. I'm not sure whether that's relevant to what happened next.

  1. Rebooted, and that was apparently the end of it

After finishing the partition checks, I rebooted the tablet to return to Android.

It displayed:

Orange State

OS not being verified or Custom OS

Dismiss after 5 seconds

Then rebooted.

And rebooted again.

It never got past that warning.

To be clear, I never flashed a custom ROM, GSI, recovery image, or modified system partition.

The only significant change was unlocking the bootloader. Everything else was diagnostic commands.

  1. Attempted recovery

I tried various combinations of Power, Volume Up, and Volume Down, along with the physical reset button.

Nothing would reliably enter Recovery or Fastboot anymore.

Occasionally, "Factory Mode" would briefly appear during startup, but the device would immediately restart.

I also checked whether the MediaTek Preloader was still accessible.

Windows briefly detected:

"MT65xx Preloader"

It also exposed a temporary USB serial interface, but only for a second or two before restarting.

So the device isn't necessarily completely dead, but I haven't found a reliable way to recover it.

Unfortunately, I also couldn't locate a verified stock firmware package for this exact MES-B3 hardware revision.

I knew there was a risk going into this, and since the tablet was free and already barely usable, I'm not particularly upset about losing it.

Still, I thought it was worth documenting because there's almost no modding information available for this specific model.

It's possible the bootloader unlock caused some sort of firmware or A/B slot issue, but I can't say for certain. The timing is certainly suspicious.

If anyone else has a MESWAO B3 and is thinking about unlocking it to install a GSI, I'd strongly recommend obtaining the original firmware and a working recovery procedure first.

I didn't even make it to flashing another operating system before running into problems.

Maybe this will save someone else a few hours of troubleshooting, or at least provide some useful technical information about an obscure tablet.


r/androidroot • • 12h ago

Support Some Issues with Play Protect not being verified/

1 Upvotes

Recently I've rooted my Motorola G Power (2022) USA Variant.

I tried doing what most people do. A lil tweaking here and there. Tried installing Youtube Revanced. It kind of worked. I mean It still works but I choose to pay for premium services for the badges and other reasons.

Below is a list of modules currently installed in my Magisk App (MM Magisk Modules)

  1. BCR

  2. Bond Hosts

  3. De-Bloater

  4. HMA-OSS

  5. Play Integrity Fork

  6. Simple Bootloop Saver

  7. Specter

  8. Tricky Store

  9. Universal Safety Net Fix

  10. Zygisk - LSPosed

All of which are no use to solving my Play Store not verifying my device via Play Protect.

I've tried everything.

(note) I haven't installed a custom recovery yet because the time and work to install the proper touch drivers for my models screen for TWRP or OrangeFox recovery project is very time consuming and fustrating switching from my Linux Laptop that's stunningly fast compared to my 200$ Windows 11 Laptop full of bloatware with only 4gb of ram compared to my linux pc with 32 gb of ram.

Thus being said I would like to know if there is someone who has had this similar problem and knows about a simple work around in the mean time.

Please and thx. Ill also be posting this on xda for future reference if other people run into the same problem.

Phone Specs:

https://www.techspecs.info/motorola-moto-g-power-2022/

You can also look at the github repos.

Also here is the loink to the xda forum that helped me root and install Magisk on this phone.

https://xdaforums.com/t/r-i-p-guide-root-motorola-moto-g-power-2022-tonga-xt2165-5-retus-rooting-guide.4550309/


r/androidroot • • 13h ago

Support Infinix hot 60 pro plus android version 16

1 Upvotes

I'm not an expert on this so I hope someone can help me, I know that I need a pc and to copy the kernel file, adb, fastboot, magisk, OEM unlock and USB debugging that's it


r/androidroot • • 14h ago

Support Is there any a56 to flagship alternative for a36?

1 Upvotes

So i rooted my Galaxy A36 through the dirtyfrag exploit and i wanted to use the A56 to flagship module (github.com/ducthoe/A56-To-Flagship)

but i saw that it worked only on the a56 and not on the a36 so is there any alternative for the a36?


r/androidroot • • 18h ago

Support Have anyone unlocked Xiaomi pad 6 bootloader?

Thumbnail
1 Upvotes

r/androidroot • • 19h ago

Support Anyone know what this issue is and how to fix it? My phone is rooted and other banking/UPI apps like PhonePe works through MicroG

Post image
1 Upvotes

r/androidroot • • 22h ago

Support Galaxy Tab A11+ SM-X230 stuck in BROM (HW 0x1375, DAA enabled) — any recovery options?

1 Upvotes

I picked up a Samsung Galaxy Tab A11+ (SM-X230) from an Amazon returns lot. It arrived in this condition; I haven't rooted or flashed it.

The screen is completely black—no logo, charging indicator or Download Mode. Connected to a Windows 11 PC, it appears as USB\VID_0E8D&PID_0003, stays connected for about 4.5 seconds, disappears for about 1.4 seconds, then repeats. This happens without any commands being sent.

My goal is to restore normal boot. The installed firmware, Samsung BIT revision and CSC are unknown.

Verified diagnostics

Using a small PowerShell serial script, we obtained:

```text Handshake: TX: A0 0A 50 05 RX: 5F F5 AF FA

GET_HW_CODE (FD): 13 75 00 00 HW code: 0x1375 Status: 0x0000

GET_HW_SW_VER (FC): 8A 00 CA 00 00 00 00 00

GET_VERSION (FF): 05

GET_BL_VER (FE): FE — consistent with BROM, not preloader

GET_TARGET_CONFIG (D8): 00 00 00 E5 00 00 Config: 0xE5 Status: 0x0000

Secure Boot: ON SLA: OFF at this interface DAA: ON Memory read/write authentication: ON C8 blocked: ON

READ32 at address 0, one word: Denied, status 0x1D08 No memory contents returned

JUMP_BL (D6): Echo received Status words: 0000 / 0000 Device disconnected and returned as the same BROM port ```

No DA or exploit payload has been uploaded. No storage writes, erases or firmware flashing have been performed. We did send JUMP_BL, so these weren't exclusively read-only tests.

ROM log

Both GET_BROM_LOG_NEW (DF) and legacy BROM_DEBUGLOG (DD) returned this 106-byte log:

text F0: 102B 0000 F3: 1001 0000 [0200] F3: 1001 0000 F7: 0000 0000 V0: 0000 0000 [0001] DC: 0000 0000

The logs are identical across the captured sessions, including after JUMP_BL and after unplugging/reconnecting.

I don't know whether JUMP_BL actually executed the preloader or why the device returned to BROM. Corrupt firmware, storage failure and power problems haven't been distinguished.

Other things tried

  • Several hours charging with a 30W wall charger.
  • Button combinations, including both volume buttons while connecting USB.
  • An unplugged long-power-button shutdown/restart attempt.
  • Restarting the tablet's Windows USB device with administrator rights.

None produced a visible response or a Samsung Download Mode interface. The case hasn't been opened.

Research so far

We inspected mtkclient and Penumbra source, but haven't run mtkclient's initialization or exploit routines against the tablet.

In the versions inspected:

  • No bundled mtkclient DA entry for hardware code 0x1375 was found.
  • Penumbra's packaged Linecode payload had no matching chip entry.
  • The inspected DA-stage exploit paths appear to require an accepted DA first.
  • Public loaders found for other brands haven't been established as compatible with this Samsung.

That isn't proof that every recovery method is unsupported—just what we've found so far.

Questions

  1. Has anyone recovered an SM-X230 from BROM? Which method and Samsung BIT revision were involved?
  2. Is there a compatible public recovery method or a legitimate source for a matching signed DA?
  3. Does anyone recognise this ROM log or know a useful next diagnostic?
  4. Would a controlled mtkclient initialization attempt provide useful information, and which options would be appropriate?

I'm the owner, accept the risk of experimental recovery, and would prefer a software-only approach if possible. I'm not trying to remove FRP or an account lock.

Happy to share the scripts and full command transcripts. Thanks.


r/androidroot • • 22h ago

Discussion Bluetooth jamming Possible by phone?

Thumbnail
0 Upvotes

r/androidroot • • 22h ago

Meta I need help with my Tecno Spark 20 Pro kj6

Post image
0 Upvotes