In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]
PoC: ghostlock-app
GhostLock One-Tap Execution App (CVE-2026-43499)
PoC: IonStack-S22U
CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)
[POC] CVE-2026-43499 — CVE-2026-43499-popsicle
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
[POC] CVE-2026-43499 — CVE-2026-43499-Neo11Plus
the CVE-2026-43499 by iqooneo11
PoC: ghostlock-s26
GhostLock (CVE-2026-43499) for the Galaxy S26
PoC: pixel-ksu-root
adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.
[POC] CVE-2026-43499 — GhostLock-Galaxy
Root your Galaxy using CVE-2026-43499
PoC: iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock
An iQOO Z9 5G and vivo T3 5G jailbreak/root CVE-2026-43499 Android application and payloads. Both devices use the MediaTek Dimensity 7200 (MT6886) platform. Kernel version 5.15.178.
PoC: Root-My-Galaxy
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
[POC] CVE-2026-43499 — Mi8E5-Unlocker-by-CVE-2026-43499
基于 CVE-2026-43499 的 8E5 机型自动化解锁辅助工具,仅限授权安全研究与自有设备使用。
[POC] CVE-2026-43499 — tcp-zerocopy-sm
ghostlock + tcp-zerocopy hybrid CVE-2026-43499 port
[POC] CVE-2026-43499 — root-my-s9280
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))
[POC] CVE-2026-43499 — ghostlock-oneplus
GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader
[POC] GHSA-8qqm-fp2q-v734 — CVE-2026-43499-S25U
Galaxy S25 Ultra SM-S938N S938NKSUACZF1 port of CVE-2026-43499
[POC] CVE-2026-43499 — GhostLock-5.10
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
[POC] CVE-2026-43499 — ghostlock-cve-2026-43499-4.19-k40
CVE-2026-43499 (GhostLock) rtmutex remove_waiter() UAF local-root PoC adapted for Qualcomm Android 4.19 kernels (Redmi K40 / Snapdragon 870 class), LD_PRELOAD based
PoC: cve-2026-43499-honor
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.
PoC: KSuRoot
KSuRoot 2.2.0 — One-click KernelSU rooting based on CVE-2026-43499. Synced from Root-My-Galaxy v0.2.6 with custom payload (.so) import. Mod by hmascs
PoC: iqoo-temp-root
vivo/iQOO 临时 root 工具箱 (免解锁临时root, CVE-2026-43499) - 源码与脚本
PoC: ghostlock-apk
独立 APK:CVE-2026-43499 GhostLock 提权 + Shizuku shell 身份执行
PoC: ghostlock-honor-aak-probe
该仓库已经确认此漏洞利用不可能实现、已判死刑,永久性停止更新。基于 CVE-2026-43499 (rtmutex remove_waiter UAF) 的 GhostLock exploit 半成品工程,KASLR 绕过 / 提权 / su 植入等环节均无法稳定利用,本项目永久终止。
PoC: ghostlock-honor-aak
GhostLock (CVE-2026-43499) exploit adapted for Honor AAK-AN00 (MagicOS 10, kernel 6.6.89-android15)
PoC: HORiZonstack
CVE-2026-43499 for the Meta Quest
PoC: CVE-2026-43499
CVE-2026-43499: Linux kernel futex PI use-after-free research package
PoC: GhostLock-for-OnePlus15T
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.
PoC: GhostLock-for-OnePlus
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加设备。
PoC: oppo-A5-PRO-5G-CVE-2026-43499
本次个人漏洞研究进展成果
PoC: SpringPeace
(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499
PoC: oppo-ghostlock
OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation
PoC: rmg-s9180-fzg1
Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM
PoC: ghostlock-infinix-hot70
Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.
PoC: vivo-root-build
vivo/iQOO 提权 so 编译(CVE-2026-43499)
PoC: RootMyVivo
One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU
PoC: ghostlock-k419-adapter
GhostLock (CVE-2026-43499) adapter for 4.19.152-perf+ Android kernel
PoC: CVE-2026-43499-NAM-AL00
Security research: CVE-2026-43499 GhostLock on Huawei Nova 9 NAM-AL00 (SM7325, HMOS 4.2, kernel 5.4.86-qgki)
PoC: CyberMeowfiaNS
The next stage of CyberMeowfil (CVE-2026-43499 and 43074),Possibly biased toward vivo devices?
PoC: GhostLock-H80GT
Honor 80 GT (MagicOS 8.0.0.128, kernel 5.10.168) privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading
PoC: GhostLock_MT6983V_5.10
High-risk vulnerability CVE-2026-43499, implementation on the 5.10 kernel and MediaTek MT6983V
PoC: s26-m1q-ghostlock-selinux
GhostLock CVE-2026-43499 research for Galaxy S26 (SM-S942U1/m1q): SELinux Permissive achieved, KASLR + tracefs port, uid=0 boundary documented
PoC: ghostlock-custom
GhostLock (CVE-2026-43499) adaptation for non-Android Linux 6.x ARM64
PoC: CVE-2026-43499_HW-CLT-AL01
尝试移植CVE-2026-43499提权漏洞到HW P20Pro上
PoC: ghostlock-cve-2026-43499
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
PoC: ghostlock-a17
CVE-2026-43499 port for Samsung Galaxy A17
PoC: IonStack-S22-cve-2026-43499
Full root in kernel domain with selinux permissive
PoC: CVE-2026-43499-ZFOLD4
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
PoC: cve-2026-43499-m3q-azf1
This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here.
PoC: GhostLock
CVE-2026-43499 futex PI stack UAF ???????? - Android GKI 6.1~6.12 ??????? pselect() + futex PI ????????????,??? root ??? SELinux??? OPPO Find X8?OnePlus ??????
PoC: F9360-CVE43499
SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko. Device-verified 2026-08-12.
PoC: GhostLock-OPPO-PCKM00
CVE-2026-43499 GhostLock futex UAF LPE PoC for OPPO PCKM00 (SM6150) / Linux 4.14.180
PoC: ghostlock-skeleton-v2
CVE-2026-43499 GhostLock APK 骨架 — 从零开始,仅空项目编译验证
PoC: ghostlock-skeleton
CVE-2026-43499 GhostLock APK 骨架 — 仅验证空项目能编译通过
PoC: ghostlock-x200-root
GhostLock-X200 v1.0 - temporary root toolchain for vivo X200 (PD2415 / b57 kernel) based on CVE-2026-43499. For authorized security research only.
PoC: GhostLock-GOT-W29
CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29
PoC: Root-My-Galaxy-tests
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499 (Note: Fork)
PoC: Root-My-Galaxy
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
PoC: ghostlock-sm-a155f
GhostLock (CVE-2026-43499) kernel exploit for samsung devices with locked bootloader
PoC: CVE-2026-43499_x86_Exploit
CVE-2026-43499 x86 Exploit
PoC: ghostlock-myron-tw
GhostLock (CVE-2026-43499) kernel exploit port for REDMI K90 Pro Max Taiwan firmware (myron, WPMTWXM) — offsets, build guide, prebuilt binary
PoC: Root-My-Pixel
Jailbreak supported Google Pixel phones with CVE-2026-43499
PoC: CVE-2026-43499-S26
Root prototype for Galaxy S26
PoC: CVE-2026-43499-A36
Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load
PoC: cve-2026-43499
PD2229B的43499(ghostlock)可行性研究
PoC: ghostlock-aresin
GhostLock (CVE-2026-43499) exploit for POCO F3 GT (aresin) — MediaTek Dimensity 1200, Linux 4.14.186 ARM64 kernel privilege escalation via futex PI chain manipulation
PoC: ghostlock-emerald
GhostLock (CVE-2026-43499) kernel exploit for Poco M6 Pro (emerald) with locked bootloader
PoC: mt6985-CVE-2026-43499
CVE-2026-43499 exploit adapter for MT6985 MediaTek Dimensity 9300 (vivo PD2241)
PoC: Root-My-Device
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
PoC: CVE-2026-43499-root-KernelSU
基于内核漏洞的本地提权适配,集成嵌入式 KernelSU 。编译生成`preload.so`;触发成功后会以 `late-load` 模式(越狱模式)启动 KernelSU。支持(xbl_config.img / vendor_boot.img) + boot.img 生成target.h Local privilege escalation adaptation based on a kernel vulnerability, integrating embedded KernelSU. Compiles and generates `preload.so`; , KernelSU will be started in `late-load` mode
PoC: CVE-2026-43499-S24U
CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (in progress)
PoC: UnPlus
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)
PoC: cve-2026-43499-CyberMeowfia
最原始的
PoC: rmx3888-cve-2026-43499-config
CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets
PoC: CVE-2026-43499-PoC-Scanner
CVE-2026-43499 PoC Scanner
PoC: Ace3-GhostLock-Preload
OnePlus Ace 3 preload.so for CVE-2026-43499 (GhostLock)
PoC: CVE-2026-43499-Redmi-Turbo5
Use CVE-2026-43499 on Redmi Turbo 5 to escalate privilege
PoC: CVE-2026-43499
CVE-2026-43499
PoC: CVE-2026-43499-cloudflare-gate
CVE-2026-43499-cloudflare-gate签名授权计算
PoC: CVE-2026-43499-For-Xiaomi-17T-chagall
CVE-2026-43499 reproduce in Xiaomi 17T. (kernelsu incomplete)
PoC: CVE-2026-43499
CVE-2026-43499
PoC: smt878u-ionstack-poc
CVE-2026-43499 (IonStack/GhostLock) pure-C re-root POC for Samsung SM-T878U / gts7l (T878USQS8DXE1)
PoC: ghostlock-selinux-disabler
Use CVE-2026-43499 to disable SELinux on Android
PoC: vivo-x-fold6-ghostlock
vivo X Fold6 (V2545A) GhostLock CVE-2026-43499 临时root/永久解锁研究
PoC: CyberMeowfia-ace3
CVE-2026-43499 exploit with OnePlus Ace3 support
PoC: CVE-2026-43499-jinghu
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
PoC: CVE-2026-43499-jinghu
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
PoC: CyberMeowfia-ace3
CVE-2026-43499 exploit with OnePlus Ace3 support
PoC: ghostlock-rothko
CVE-2026-43499 GhostLock exploit for Redmi K70 Ultra (rothko) - data-only physmap overwrite
PoC: CVE-2026-43499-popsicle
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
PoC: auto_extract_offsets
CvE-2026-43499偏移量计算
PoC: CVE-2026-43499
A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia
PoC: duchamp-root
Xiaomi K70e (duchamp) one-click root via CVE-2026-43499 (IonStack) + KernelSU integration
PoC: Logitech-G-Cloud-GhostLock-CVE-2026-43499
罗技云掌机 · GhostLock CVE-2026-43499 root 尝试
PoC: CVE-2026-43499-Poc-Analysis
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
PoC: CVE-2026-43499-Poc-Analysis
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
PoC: SpringPeace
(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499
PoC: Android-CVE-2026-43499
Android version CVE-2026-43499 tester
PoC: oppo-pgem10-ghostlock
OPPO Find X6 Pro GhostLock (CVE-2026-43499) exploit adaptation
PoC: Mi8E5-Unlocker-by-CVE-2026-43499
Multi OS Support: Version for MacOS/Linux and Windows, Fully translated to English
PoC: openvz-cve-patch-2026
GhostLock - CVE-2026-43499 backport patch for openVZ 7
PoC: ghostlock
Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free
PoC: CVE-2026-43499
CVE-2026-43499
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free