ShizuStore

SMT Shell

BLuFeNiX

2.0 · GitHub

Download APK
Vendor-specific Android 5.1+ 3 years ago LGPL-2.1
68 ShizuStore
12.4k GitHub
249 Stars
17 MB Size

More about this app

Privilege escalation exploit [(CVE-2019-16253)](https://nvd.nist.gov/vuln/detail/CVE-2019-16253) to system user access (UID 1000) on non-rooted devices running up to OneUI 5. Uses Shizuku for automation

SMTShell

This tool allows most Samsung devices to achieve a system shell (UID 1000). It was patched in OneUI 5.1, but will work on Android 13 running OneUI 5.0 or older. It should work as far back and Android 9.0 (and maybe earlier).

It also acts similar to Magisk or SuperSU, allowing apps to easily execute system commands via SMTShell-API.

Usage (with Shizuku)

Simply run the app and grant Shizuku access.

Usage (no Shizuku)

  1. Downgrade the TTS app to the version provided (this must be done after every reboot):
adb install -d com.samsung.SMT_v3.0.02.2.apk

Alternatively, you can use pm install -d /data/local/tmp/com.samsung.SMT_v3.0.02.2.apk if you copy the file to your device first, via adb push

  1. Install and open the SMT Shell app, and follow the prompts.

Licences & Origin

This project started as a fork of SMT-CVE-2019-16253, created by flankerhqd (AKA flanker017). There is also a write-up by flanker here. Due to the original repo containing multiple unrelated projects, this fork's git history was rewritten using git filter-repo so that it only contains the relevant code (and no prebuilt artifacts).

This repo will continue to use the LGPL license that the original used when this fork was created. Other embedded components are licensed as follows:

Shizuku - Copyright (c) 2021 RikkaW

Some code was copied or adapted from the Shizuku API demo project, which is distributed under the MIT License. Primarily, this includes files in smtshell/app/src/main/java/com/samsung/SMT/lang/smtshell/shizuku, and the hidden API class stubs in smtshell/hidden-api-stub. A copy of the license can be found here.

Samsung

This project includes an unmodified Samsung APK, at ./smtshell/app/src/main/assets/com.samsung.SMT_v3.0.02.2.apk.

Changes from the original

Please see the git commit history for a comprehensive list of changes. Essentially everything was changed, and only the original exploit research remains in spirit.

Close

How Shizuku is used

Can downgrade the Samsung SMT app to a vulnerable version via a `PackageInstaller` session through Shizuku.

This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.

How this app uses Shizuku

Shizuku is used to automate installing a bundled older Samsung SMT build so the exploit can run.

  • Downgrade Samsung app: when the installed Samsung text to speech app is too new, the app installs its bundled older copy through Shizuku with replace and downgrade allowed, appearing as an install from the shell package.

Android APIs or commands used

  • IPackageManager.getPackageInstaller
  • IPackageInstaller.openSession
  • PackageInstaller.createSession
  • PackageInstaller.Session.openWrite
  • PackageInstaller.Session.commit

Notable details

Without Shizuku the same downgrade must be done manually before the exploit can run. The later system shell, commands and library loading run from the exploited system process, not through Shizuku.

Close

Changelog

What's new for version 2.0

Fixed keyboard [enter] detection in terminal.

Close

Permissions

6 permissions requested

  • smtshell.permission.SELF
  • android.permission.QUERY_ALL_PACKAGES
  • android.permission.REQUEST_DELETE_PACKAGES
  • android.permission.INTERNET
  • moe.shizuku.manager.permission.API_V23
  • com.samsung.SMT.lang.smtshell.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Close