r/androidroot 18h ago

Discussion Pixel 11 Pro Kernel CVE-2026-43499

I have been doing some rummaging around and it seems like with kernel 6.12.69 that the vulnerability may remain exposed. All indicators point to anything post 6.12.86 as being safe from the exploit.

While the security patch is in August the Kernel is dated just 7/10 which gives me some hope that it's possible to achieve bootloader locked temporal root. I utilized the cve-2026-43499 application that tests whether the kernel is impervious or vulnerable. With 5/5 iterations and no kernel panic causing reboot or outright crash indicating protected. Out of 3 attempts it crashed near immediately and did not power back on without my doing so (responsively but not self rebooted).

I also see that the series leaves out a feature that is / was notable in hardening against the attack. I however am not an expert on this realm by any means and wish to either stoke a flame or be extinguished with knowledge.

That said I have testDPC as device owner (morphe patched to prevent play updates and self asserted no uninstall) with this software update policy set to postpone until 08/31/2030. I initially rooted it but the fact it refuses to pass certification despite all efforts made me circle back to a twice over full OTA application. I know from my galaxy that the capabilities and stability were plenty favorable and reattaining root post reboot was in my opinion a small task for what expanded patches and modules could be applied.

That is all please affirm my desire.

27 Upvotes

5 comments sorted by

4

u/Tornado15550 15h ago

This is the beauty of GKI where you can install the latest upstream LTS kernel version if you're rooted.

Here's my Pixel 10 Pro XL running a relatively new 6.12 LTS kernel.

1

u/The_Band_Geek 7h ago

Does this apply to all rooted Android phones, or strictly Pixels? I wouldn't mind updating the kernel on my Moto edge+ 2023.

1

u/SchoolinAndCoolin 3h ago

This is the result of using wildsu to patch the boot image and flashing that to the device at least I believe it to be. I had initially unlocked my bootloader and used pixelflasher to do so and initially rooted with magisk and subsequently flashed the k3 file produced via the app patch. 

I don't know that I saw anything of kernel hardening among any of the browsing I did. It's cool but can you use Google Wallet or even if you show strong integrity do you have play certification? These small bits were enough for me to undo it and find otherwise. 

1

u/_iAmWiz 5h ago

What's your DPI/smallest width?

1

u/SchoolinAndCoolin 3h ago

Text scaled to 85% and DPI 380 applied via rish in  termux