One-tap root for Samsung Galaxy devices — New exploit (DirtyFrag CVE-2026-43284, unprivileged) + Old exploit profiles, with auto-root at every boot.
Made by kuuky.
I am not responsible for bricked phones.
- New exploit (fast) — the unprivileged DirtyFrag engine (CVE-2026-43284): IpSecManager allocates the SA, the native engine corrupts the kernel page cache, ksud is late-loaded from memory. No profile, no Shizuku, no setup — press Root now.
- ksud updater, in the app — a full-width button (New exploit section) downloads the latest official ksud (KernelSU Next or classic, per the selected flavor) and patches it on device with the bundled Samsung KDP+DEFEX .kos, then the result is used immediately (Next → auto-selected profile, classic →
ksud-classic-latest). Already updated? → "you are already updated". - ksud profiles — profile bands (same style as the old exploit profiles) for both flavors: bundled + downloaded profiles, selectable, and deletable from Advanced settings.
- Auto-root at boot — a foreground boot service waits for the first unlock and re-runs the chain (up to 6 attempts), with a partial WakeLock so the phone can't sleep mid-exploit.
- Progress UI — animated progress bar with live engine stages (IpSec SA → SPI → ksud staged → arming → Phone rooted ✓), and a bottom progress popup for the ksud updater. Fully in English.
- Root state banner — clean Rooted / Not rooted banner driven by a live
su -c idprobe (no more false "rooted" after a reboot).
The classic profile pipeline stays untouched: CVE-2026-43499 payloads (local or Shizuku), Root My Galaxy integration, per-device validated profiles (S25 ZZHL/ZZI4, S26 Ultra ZZHK, S93XX, Oppo), profile editor, instant root, and run-log archives.
./gradlew assembleRelease # -> app/build/outputs/apk/release/This app stands on the shoulders of:
- diabl0w — DFRoot: the DirtyFrag engine this whole project is built around
- snothin — GhostSam: the Samsung-patched kos, the ksud patching approach and the staged native API
- polygraphene — the DFRoot fork lineage and the DEFEX bypass work
- tiann — KernelSU
- rifsxd & the KernelSU-Next team — KernelSU-Next
- YuKongA — GhostLock: the UI this app's interface is based on
Thank you all 🙏