Root My Pixel
1.5 · GitHub
More about this app
Root automation for Pixel devices via CVE-2026-43499 exploit
Root My Pixel
Root My Pixel is an Android application designed to automate root access on Google Pixel devices leveraging the NebuSec IonStack exploit (CVE-2026-43499) and integrating ReSukiSU / KernelSU.
How the Application Works
Root My Pixel lets you temporarily gain root access with ReSukiSU in just one tap.
Installation Workflow
Device Detection & Profiling
- At startup, the app uses native JNI (
NativeProbe),/proc/versionqueries, and system properties to detect the device codename, kernel version, CPU ABI, memory page size, and build display ID. - Via
ResolveTargetUseCase, it matches the device details against supported target profiles defined inassets/profiles.json.
- At startup, the app uses native JNI (
Shizuku Integration
- The app uses Shizuku (UID 2000) to acquire ADB shell privileges without needing initial root access, which is required to stage and execute payload binaries in
/data/local/tmp. - A managed
ExploitServiceis bound via Binder IPC to stream exploit execution logs to the UI in real time.
- The app uses Shizuku (UID 2000) to acquire ADB shell privileges without needing initial root access, which is required to stage and execute payload binaries in
Exploit Payload Extraction & Execution
- Precompiled binary payloads (
.so) corresponding to each supported build and the native helper tool (libcve43499root.so) are extracted from APK assets to/data/local/tmp. - The IonStack exploit (CVE-2026-43499) is executed to establish a local root daemon socket (
temp_su.sock), acquiring fullrootprivileges.
- Precompiled binary payloads (
KernelSU / ReSukiSU Integration
- Staging of the
ksudbinary matching the device's Kernel Module Interface (KMI, e.g.,android15-6.6). - The app triggers the KernelSU late-load mechanism (
ksud late-load --kmi <kmi>). - Verifies KernelSU through its UAPI, with
ksud debug infoand/proc/modulesas compatibility fallbacks. - Registers the installed ReSukiSU Manager only after validating its production APK signature.
- Staging of the
User Interface & Management Tools
- Real-time live log progress monitoring.
- Handy actions for Soft Reboot (restarting
system_server) and Log Exporting for debugging purposes.
Supported Devices & Build Profiles
| Device | Codename | Supported Builds | Kernel KMI | Tested |
|---|---|---|---|---|
| Pixel 11 | cubs |
CD1A.260618.001.C2 |
android16-6.12 |
✅ |
| Pixel 11 Pro | grizzly |
CD1A.260618.001.C2 |
android16-6.12 |
✅ |
| Pixel 11 Pro XL | kodiak |
CD1A.260618.001.C2 |
android16-6.12 |
✅ |
| Pixel 11 Pro Fold | yogi |
CD1A.260618.001.C3 |
android16-6.12 |
✅ |
| Pixel 10 | frankel |
CP2A.260705.006 |
android15-6.6 |
✅ |
| Pixel 10 Pro | blazer |
CP2A.260705.006 |
android15-6.6 |
✅ |
| Pixel 10 Pro XL | mustang |
CP2A.260705.006CP2A.260805.005 |
android15-6.6 |
✅ |
| Pixel 10 Pro Fold | rango |
CP2A.260705.006 |
android15-6.6 |
✅ |
| Pixel 10a | stallion |
CP2A.260705.006CP2A.260805.005 |
android14-6.1 |
✅ |
| Pixel 9 Pro Fold | comet |
CP2A.260705.006 |
android15-6.1 |
✅ |
| Pixel 9 Pro | caiman |
CP2A.260705.006 |
android15-6.1 |
✅ |
| Pixel 9 Pro XL | komodo |
CP2A.260705.006 |
android15-6.1 |
✅ |
| Pixel 9 | tokay |
CP2A.260705.006AD1A.240905.004 |
android14-6.1 |
✅ |
| Pixel 9a | tegu |
CP2A.260705.006 |
android14-6.1 |
✅ |
| Pixel 8 Pro | husky |
CP2A.260705.006 |
android14-6.1 |
✅ |
| Pixel 8 | shiba |
CP2A.260705.006 |
android14-6.1 |
✅ |
| Pixel 8a | akita |
CP2A.260805.005 |
android14-6.1 |
✅ |
| Pixel 7a | lynx |
CP2A.260705.006 |
android14-6.1 |
✅ |
| Pixel 7 Pro | cheetah |
CP2A.260705.006 |
android14-6.1 |
✅ |
| Pixel 7 | panther |
CP2A.260705.006BP2A.250705.008 |
android14-6.1 |
✅ |
| Pixel 6a | bluejay |
CP2A.260705.006CP1A.260405.005 |
android14-6.1 |
✅ |
| Pixel 6 | oriole |
CP2A.260705.006 |
android14-6.1 |
✅ |
| Pixel 6 Pro | raven |
CP2A.260705.006 |
android14-6.1 |
✅ |
| Pixel Fold | felix |
CP2A.260605.012CP2A.260705.006 |
android14-6.1 |
✅ |
| Pixel Tablet | tangorpro |
BP1A.250405.007CP2A.260705.006 |
android14-6.1 |
✅ |
Prerequisites
- A supported Google Pixel device listed in the table above.
- Shizuku installed and running via ADB (
adb shell sh /sdcard/Android/data/rikka.shizuku/starter.shor Wireless Debugging). - ReSukiSU Manager installed on the device to manage root permissions granted to apps.
Building from Source
To compile the entire project (native helper, exploit payloads for all targets, and the final debug APK):
Build Requirements
- Android NDK r25+ (
ANDROID_NDK_HOMEset or present in Android SDK) - macOS (arm64/x86_64) or Linux (x86_64) host
- Java 17+ and Gradle Wrapper
Build Command
./build-all.sh
The compiled APK will be generated at:
app/build/outputs/apk/debug/app-debug.apk
To install it on a connected device via ADB:
adb install -r app/build/outputs/apk/debug/app-debug.apk
⚠️ Keep in mind that the exploit does not have a 100% success rate. Many users have had to try more than 20 times. Many report higher success by opening the app immediately after a reboot, while others find better results 10–40 minutes after rebooting.
🚨 If you root your phone, you might run into trouble making payments with Google Wallet and using RCS messages. Once you unroot, you'll have to wait a couple of days before everything works properly again.
Credits
- Exploit: NebuSec IonStack
- App architecture: Inspired and adapted from Root My Galaxy
- ReSukiSU (https://github.com/ReSukiSU/ReSukiSU)
How Shizuku is used
Can run a root exploit, clean up root state and reboot the device via Shizuku shell with `/system/bin/sh -c`.
This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.
How this app uses Shizuku
Shizuku shell access is used to run the Pixel root flow and to clean up afterwards. The install step requires Shizuku, while cleanup and reboot also try other root options first.
- Run root exploit: the app starts its bundled exploit payload through Shizuku to gain root and set up root management, and streams the exploit log back to the install screen for progress.
- Check root access: the app runs a root identity check through the Shizuku shell to confirm whether the exploit root shell is available for later cleanup.
- Remove root state: the app runs its bundled unroot cleanup script through the Shizuku shell to delete exploit files, root binaries, logs and temporary state and restore enforcing mode.
- Reboot device: after cleanup the app requests a reboot through the Shizuku shell to finish applying the restored state.
Android APIs or commands used
/system/bin/sh -ccat /data/local/tmp/exploit.logid -u/data/local/tmp/su -csyncsvc power rebootrebootBinder.getCallingUid
Notable details
Root installation requires Shizuku shell access and does not proceed without it. Unroot cleanup and reboot can also work without Shizuku when the app already has root through its root manager grant or the current-install helper, with Shizuku used as an additional transport.
Changelog
What's new for version 1.5
What's Changed
- fix: verify ReSukiSU late-load and manager by @alex193a in https://github.com/alex193a/Root-My-Pixel/pull/63
- Add Pixel 11 family support
- Add Pixel Tablet support
- Add Pixel Fold support
- Minor bugfixes
Full Changelog: https://github.com/alex193a/Root-My-Pixel/compare/v1.4...v1.5
Permissions
3 permissions requested