We have successfully cracked the community account level restriction for HyperOS BootLoader unlocking! It works fine on Xiaomi 14 and theoretically works on all devices running HyperOS (including those upgraded from MIUI). (1/2)
There's a good and a bad.
The good is: We went ahead and made the PoC for exploiting the vulnerability public, it's free and you can check it out in GitHub:
The exploit principle will be explained later. Feel free pull request if you want :)
After successful binding, you still need to wait according to the unlock limit before the HyperOS update. We will release the full PHP script and PoC workaround after the test machine is successfully unlocked. (2/2)
The bad is: According to our tests, Xiaomi has added a logic to force verification of account qualification for some devices in the PC's unlocking tool, which is based on model. This means that even if the phone binding is successful, you still won't be able to unlock.
Qin F21 Pro unlocked and Magisk-ed.
Thanks for
@viperbjk
's mtkclient. Added some of my own little magic😋.
Android 11, official Magisk 23.0 works well.
After updating to the latest HyperOS, some model will error 10000 when use bypass script.
This is because Xiaomi has changed log encryption algorithm from AES to hybrid RSA+AES in Settings. RSA is asymmetric, can't be decrypted without private key, so script don't work. (1/n)
There's a good and a bad.
The good is: We went ahead and made the PoC for exploiting the vulnerability public, it's free and you can check it out in GitHub:
The exploit principle will be explained later. Feel free pull request if you want :)
Finally finished it. I did some device-specific processes using php. Thanks to
@viperbjk
for mtkclient.
* Crack BootLoader without erasing userdata.
! Remember to keep the backup properly, they are needed for relock or OTA.
It's so clean! With OPlus' LTW blobs, we can easily add Phone Link feature to AOSP-like ROMs. I've done initial testing on
@Unihertz
Jelly Star and will add it in the next release of
@KaleidoscopeOS
. Let's see what happens.
OnePlus and OPPO are integrating Microsoft's Link to Windows app into OxygenOS 14/ColorOS 14!
At ODC23 (OPPO Developer Conference 2023), the company announced (via
@realMlgmXyysd
) it would bring Phone Link integration to ColorOS 14. OnePlus followed up with a post on its