| Fingerprint | `samsung/pa3qksx/pa3q:17/CP2A.260605.016/S938NKSUCDZIF_OKRCDZIF:user/release-keys` |
| Kernel | `6.6.127-android15-8-p33f4ffe-abogkiS938NKSUCDZIF-4k` |
| KernelSU flavour | KernelSU- `v3.4.0`, KMI `android15-6.6` |
The support feed contains one entry, `pa3q-S938NKSUCDZIF-ksun340`. Do not use its
offsets, exploit, or KernelSU pair on another model or firmware. The app selects by
model and kernel version; check the full firmware fingerprint above before running it.
- The device-specific CVE-2026-43499 app payload in
- The paired KernelSU- daemon and module in `kernelsu/`.
- The target profile and P0 fingerprint under
- One schema-v3 support-feed entry in `support/targets-v3.json`.
The payload and KernelSU pair compile in GitHub Actions. The handset's KernelSU-
Manager has shown `Working` in LKM/GKI2 mode. A Root My Galaxy run on this profile
confirmed KernelSU through the native probe, Shizuku `su`, and the kernel module
list; the helper's own report was empty in that run.
In Root My Galaxy, open **Payload sources** and add:
HaSiyo/Root-My-Galaxy-Payloads-S938NKSUCDZIF-KernelSU-
Choose the `SM-S938N` / `6.6.127` KernelSU- profile only when the full build
fingerprint above matches your phone. KernelSU is loaded for the current boot;
Build the exploit payload with Android NDK r28c:
`build/pa3q-S938NKSUCDZIF/cve-2026-43499-app.so`. The **Exploit** Actions workflow
compiles the target from this repository's support feed. The **KernelSU** workflow
builds the paired KernelSU- module and daemon for the exact kernel release above
- The target-specific exploit and KernelSU- pair passed GitHub Actions builds.
- Firmware identity and kernel release were checked against the supplied device
- A handset run confirmed KernelSU active using three independent control checks:
the native probe, Shizuku `su`, and the kernel module list.
See the [device port report](docs/ports/pa3q-S938NKSUCDZIF/port-report.md) for the
audit and remaining runtime checks, and [PORTING.md](docs/PORTING.md) for the
Use only on a device you own or are explicitly authorized to test. This is a
firmware-specific research payload, not a general Samsung root package.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
