TGViewer
Android - Reddit Android - Reddit @reddit_android · 1.29K subscribers
Post #34605 96
Got Root on my S22 Ultra! Ported CVE-2026-43499 exploit (Android 15)

Hey everyone,

I just published a port of the CVE-2026-43499 exploit for the Samsung Galaxy S22 Ultra (codename: `b0q` / SM-S908W). The exploit successfully establishes an arbitrary read/write primitive, switches SELinux to permissive, and spawns a root helper daemon, giving you full root access.

**Status:** This vulnerability is **currently UNPATCHED** by Samsung and works on the absolute latest firmware available!

🔗 **Repo Link:** https://github.com/sarabpal-dev/IonStack-S22U

**Currently Supported Target:**

* **Device:** Samsung Galaxy S22 Ultra (SM-S908W)

* **Android:** 15 / SDK 35

* **Firmware:** `AP3A.240905.015.A2.S908WVLS8FYG7`

* **Kernel:** 5.10.226-android12-9-30958166-abS908WVLS8FYG7

* **Architecture:** aarch64

\### ⚠️ Reliability & Kernel Panic Warning

Because the exploit relies on a race condition and precise timing, it can be somewhat unreliable and may trigger a kernel panic on bad runs.

**Tips for success:** For the highest success rate, **reboot your device** before running it to ensure a clean heap state. Close all background apps, keep the screen unlocked, and do not touch the phone while the exploit is running so background tasks don't disturb the timing.

\### 🛠️ Porting to other firmwares / Generating `target.h`

The offsets in the repo are specific to the firmware version listed above. If you are on a different build, you need to generate your own `target.h` file by extracting kernel symbols and offsets from your specific kernel binary.

Here is how to do it:

1. **Extract the uncompressed kernel binary (`Image`)** from your device's `boot.img`.

2. Follow the step-by-step instructions in the `target_generator` directory to install dependencies, compile the `kallsyms` extractor, and run the generator script.

👉 **[Full step-by-step instructions for the target generator can be found here\](https://github.com/sarabpal-dev/IonStack-S22U/blob/main/target_generator/README.md)**

Once you generate your `target.h`, place it in `src/targets/<YOUR_FIRMWARE_VERSION>/target.h` and compile using `make PROJECT=<YOUR_FIRMWARE_VERSION>`.

\### 🚀 How to Deploy and Run

Once compiled, push the binaries to your device:

```bash

adb push build/S908WVLS8FYG7/bin/cve-2026-43499 /data/local/tmp/cve-2026-43499

adb push build/S908WVLS8FYG7/bin/cve-2026-43499-root /data/local/tmp/cve-2026-43499-root

adb push build/S908WVLS8FYG7/bin/cve-exp32 /data/local/tmp/cve-exp32

adb shell chmod 755 /data/local/tmp/cve-2026-43499 /data/local/tmp/cve-2026-43499-root /data/local/tmp/cve-exp32

```

Execute the exploit stage to start the root daemon (it will automatically retry up to 16 times if it fails):

```bash

adb shell "LD_PRELOAD=/data/local/tmp/cve-2026-43499 sh"

```

Once successful, pop an interactive root shell:

```bash

adb shell "/data/local/tmp/cve-2026-43499-root"

```

\### 🤝 Contributions & Pull Requests

I'd love to make this exploit more stable. If you have ideas to improve reliability, optimize the futex choreography, **Pull Requests are highly appreciated and welcome!**

Check out the repo for the full source code, build instructions, and technical details on the porting changes from the v6.6 kernel to the v5.10 kernel. Technically it should work on all firmware and all varients of s22 family need to put just target.h. Please dont ask for port to other devices its impossible without having real device on hand other devices can check Root-My-Galaxy repo

https://redd.it/1vjndfi
@reddit_android
GitHub GitHub - sarabpal-dev/IonStack-S22U: CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel) CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel) - sarabpal-dev/IonStack-S22U
More from @reddit_android
  1. Oct 3, 2026Large camera, large battery heavyweight: Vivo X Fold6 Review https://www.notebookcheck.net…
  2. Oct 3, 2026Google already rolling out Android 17 QPR3 Beta 1 for Pixel https://9to5google.com/2026/10…
  3. Oct 3, 2026Inside Googlebook with Dieter Bohn https://www.youtube.com/watch?v=QChxpOUxLDY https://red…
  4. Oct 3, 2026Pixel 10a gets a $100 price hike, now starting at $599 https://9to5google.com/2026/10/02/g…
  5. Oct 3, 2026Inside Huawei's “Folded” Chip: Kirin 9050 Pro Deep Dive! https://www.youtube.com/watch?v=P…
  6. Oct 3, 2026Nvidia Shield TV Pro is now $299 – a $100 price hike seven years after the Android TV box…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →