| Fingerprint | `samsung/pa3qksx/pa3q:17/CP2A.260605.016/S938NKSUCDZIF_OKRCDZIF:user/release-keys` |
| Kernel | `6.6.127-android15-8-p33f4ffe-abogkiS938NKSUCDZIF-4k` |
| KernelSU flavour | KernelSU- `v3.4.0`, KMI `android15-6.6` |
The support feed contains one entry, `pa3q-S938NKSUCDZIF-ksun340`. Do not use its offsets, exploit, or KernelSU pair on another model or firmware. The app selects by model and kernel version; check the full firmware fingerprint above before running it.
- The device-specific CVE-2026-43499 app payload in `artifacts/pa3q-S938NKSUCDZIF/`.
- The paired KernelSU- daemon and module in `kernelsu/`.
- The target profile and P0 fingerprint under `src/targets/pa3q-S938NKSUCDZIF/`.
- One schema-v3 support-feed entry in `support/targets-v3.json`.
The payload and KernelSU pair compile in GitHub Actions. The handset's KernelSU- Manager has shown `Working` in LKM/GKI2 mode, while Root My Galaxy reported that it could not verify the control connection. The payload-side helper now returns a structured KernelSU control report. The refreshed helper must be present in the app build for that report to be consumed; a successful CI build alone does not verify a device run.
In Root My Galaxy's Payload sources settings, add:
HaSiyo/Root-My-Galaxy-Payloads-S938NKSUCDZIF
Select the `SM-S938N` / `6.6.127` KernelSU- entry only when the full build fingerprint matches this README. KernelSU is loaded for the current boot; rebooting clears the live kernel state.
Build the exploit payload with Android NDK r28c:
make TARGET=pa3q-S938NKSUCDZIF ANDROID_NDK_HOME=/path/to/android-ndk
The main output is `build/pa3q-S938NKSUCDZIF/cve-2026-43499-app.so`. The `Exploit` Actions workflow compiles the published target from this repository's feed. The `KernelSU` workflow builds the device-paired KernelSU- module and daemon; use the exact kernel release above and `v3.4.0`.
- The target-specific exploit build and KernelSU- pair passed GitHub Actions builds.
- The firmware identity and kernel release were checked against the supplied device properties and AP/BL firmware archives.
- A complete end-to-end run with the refreshed app helper has not yet been confirmed on the handset.
See [`docs/ports/pa3q-S938NKSUCDZIF/port-report.md`](docs/ports/pa3q-S938NKSUCDZIF/port-report.md) for the device audit and remaining runtime checks, and [`docs/PORTING.md`](docs/PORTING.md) for the general porting method.
Use only on a device you own or are explicitly authorized to test. This is a firmware-specific research payload, not a general Samsung root package.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
