Samsung can be rooted again without losing Knox. But there's a big catch

  • The Root My Galaxy tool uses a Linux kernel vulnerability to temporarily gain root privileges
  • It doesn't require unlocking the bootloader, doesn't erase data, and doesn't trip the Knox fuse
  • Privileges disappear after each restart, and the August patch will likely close the vulnerability

Sdílejte:
Jakub Kárník
Jakub Kárník
7. 8. 2026 10:30
galaxy s25 ultra modrá
Advertisement

The modding scene around Samsung has been in decline for years. Knox trips a physical fuse when the bootloader is unlocked, and with it, Secure Folder and wallet payments irreversibly disappear. With One UI 8, Samsung has also practically disabled bootloader unlocking in several key countries. Now, a tool has emerged that takes a different approach – through a kernel vulnerability.

Root that doesn’t trip the fuse

The open-source tool Root My Galaxy by developer busung utilizes the vulnerability CVE-2026-43499, codenamed GhostLock. It’s a use-after-free bug in memory lock management within the Linux kernel with a severity rating of 7.8, disclosed on July 7 – coincidentally two days after Samsung’s July security patch was released.

The crucial aspect is how it works. The tool elevates privileges in memory and injects the KernelSU manager without touching the bootloader. The bootloader remains locked, the Knox fuse is not tripped, and phone data is not erased. Practically, this means Secure Folder, Samsung Wallet, and banking apps continue to function, and the phone still passes Play Integrity checks. However, some security-focused applications might detect the installed KernelSU manager and refuse to launch.

Catch number one: it only survives until a restart

This is a so-called soft root. Privileges disappear with each phone restart, and you have to re-acquire them. Surprisingly, this is sufficient for many things – ad blocking via the hosts file, complete backup of applications with data, a firewall restricting individual applications’ network access, or removing pre-installed software are one-time interventions that survive a restart.

Conversely, modules intended to run permanently in the background fare poorly. You’ll have to set them up from scratch after each restart.

Catch number two: short lifespan

Support is very narrow. The tool primarily targets phones with Snapdragon 8 Elite and kernel version 6.6.98; devices with Exynos processors are currently out of play. Furthermore, sources differ on which patch it still works with: according to some, on June and older, while others claim some users succeeded even on the July patch.

Either way, it’s true that the August security patch will likely close the vulnerability. And here’s the unpleasant part of the equation: whoever wants to keep root must freeze their phone at a security level that will become older each month. You’re essentially trading real security for the ability to customize your system.

Do you miss the time when phones could be freely customized, or do you no longer care today?

Sources: Android Authority, SammyGuru, Gadget Hacks

About the author

Jakub Kárník

Jakub is known for his endless curiosity and passion for the latest technologies. His love for mobile phones started with an iPhone 3G, but nowadays… More about the author

Jakub Kárník
Sdílejte: