en
Feedback
LSPosed

LSPosed

Open in Telegram

Official webpage: lsposed.org Discussion Group: @LSPosedDiscussion CI Builds: @LSPosedArchives Admin Log: @lsposed_log

Show more

📈 Analytical overview of Telegram channel LSPosed

Channel LSPosed (@lsposed) in the English language segment is an active participant. Currently, the community unites 190 381 subscribers, ranking 539 in the Technologies & Applications category and 561 in the China region.

📊 Audience metrics and dynamics

Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 190 381 subscribers.

According to the latest data from 26 August, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 5 099 over the last 30 days and by 183 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 76.68%. Within the first 24 hours after publication, content typically collects N/A% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 0 views. Within the first day, a publication typically gains 0 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 0.

📝 Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
Official webpage: lsposed.org Discussion Group: @LSPosedDiscussion CI Builds: @LSPosedArchives Admin Log: @lsposed_log

Thanks to the high frequency of updates (latest data received on 27 August, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

190 381
Subscribers
+18324 hours
+1 2517 days
+5 09930 days
Posts Archive
LSPosed
190 393
我们在 Android 17.0 中发现了一个特权进程任意代码执行漏洞。该漏洞已在 Android 17 QPR1 中修复,但 AOSP 安全公告中并未提及。结合 dirty frag 漏洞(CVE-2026-43284),我们在 Android 17.0 上成功实现了完整的 root 权限提升。 这是一个典型的 1day 漏洞。尽管补丁已发布,但用户无法获得漏洞修复,因此仍面临被攻击的风险:任何人都可以通过对比分析发现该漏洞的细节。而 dirty frag 漏洞虽已于三个月前披露,但至今仍可被利用。这是因为谷歌推迟了漏洞补丁的发布频率,将安全公告从每月一次改为每季度一次。在 AI 时代,这种做法不可理喻。由于 Pixel 系统镜像中泄露的漏洞细节,Android 生态中的大量设备都容易受到攻击,未参与 Beta 测试计划的 Pixel 设备也无法幸免。 因此,我们利用两个“已经”修复过的漏洞,演示了对安装有最新安全补丁的 CP2A.260705.006 稳定版系统 Google Pixel 10 设备获取 root 权限的操作,以此作为警示,敦促 Google 改变其做法并及时发布漏洞补丁。

LSPosed
190 393
We discovered a privileged process arbitrary code execution vulnerability in Android 17. This vulnerability was patched in Android 17 QPR1 but was not included in any security bulletin. Combined with the dirty frag vulnerability (CVE-2026-43284), we achieved full root privilege escalation on Android 17.0. The DirtyFrag vulnerability was disclosed 3 months ago but is still exploitabe, because Google has delayed the release frequency of vulnerability patches, changing from monthly to quarterly security bulletins. In the AI ​​era, this behavior is completely incomprehensible. A large number of devices in the Android ecosystem are vulnerable to attacks due to the vulnerability details leaked in the Pixel system; even Pixel devices not participating in the beta program are not immune. Therefore, we used two "already patched" vulnerabilities to demonstrate full rooting on Google Pixel 10 with the latest patches as a warning, urging Google to change its practices and release vulnerability patches promptly.

LSPosed
190 393
v2.1.1
新增 - 最低支持版本提升至 Android 9(API 28) - 高级隐藏功能现可支持 A12+ - 允许一键清空已选作用域 改进 - 优化安全模式对 System UI 的检测阈值 - 恢复管理器中的模块数量徽标 - 改进错误报告发送流程 修复 - 修复部分情况下无法启动守护进程的问题 - 修复 XposedHelpers.findField API 行为 - 修复 Android 17 下服务连接接口不兼容的问题 - 修复模块详情页弹出菜单显示层级异常的问题 - 修复 Markdown 样式在部分页面中显示异常的问题 Added - Raised the minimum supported version to Android 9 (API 28) - Advanced hiding is now supported on Android 12 and above - Added an option to clear all selected scope apps Improved - Optimized the System UI detection threshold in safe mode - Restored the module count badge in the manager - Improved the error report submission process Fixed - Fixed an issue that could prevent the daemon from starting - Fixed the behavior of the XposedHelpers.findField API - Fixed service connection incompatibility on Android 17 - Fixed incorrect popup menu layering on the module details page - Fixed Markdown styles being displayed incorrectly on some pages

LSPosed
190 393
v2.1.1
新增 - 最低支持版本提升至 Android 9(API 28) - 高级隐藏功能现可支持 A12+ - 允许一键清空已选作用域 改进 - 优化安全模式对 System UI 的检测阈值 - 恢复管理器中的模块数量徽标 - 改进错误报告发送流程 修复 - 修复部分情况下无法启动守护进程的问题 - 修复 XposedHelpers.findField API 行为 - 修复 Android 17 下服务连接接口不兼容的问题 - 修复模块详情页弹出菜单显示层级异常的问题 - 修复 Markdown 样式在部分页面中显示异常的问题 Added - Raised the minimum supported version to Android 9 (API 28) - Advanced hiding is now supported on Android 12 and above - Added an option to clear all selected scope apps Improved - Optimized the System UI detection threshold in safe mode - Restored the module count badge in the manager - Improved the error report submission process Fixed - Fixed an issue that could prevent the daemon from starting - Fixed the behavior of the XposedHelpers.findField API - Fixed service connection incompatibility on Android 17 - Fixed incorrect popup menu layering on the module details page - Fixed Markdown styles being displayed incorrectly on some pages

LSPosed
190 393
Successfully root my K90PM using CVE-2026-43499

LSPosed
190 393
v2.1.0 新增 实现 libxposed API 102 适配 Android 17 QPR1 Beta 4 维护 原计划 2.1.0 废弃 New XSharedPreferences 推迟到 2.2.0,强烈建议 legacy 模块尽快迁移到 libxposed 今后可向 report@bug.lsposed.org 发送反馈邮件 改进 大幅提升被 hook 方法的性能 优化还原内联钩子逻辑 优化 dex 优化器包装的挂载逻辑 优化一系列的 UI 体验 修复 修复 XposedBridge.unhookMethod 行为异常 修复了一个全局检测点 修复 TalkBack 重复朗读、未朗读勾选状态等无障碍问题 Added Implemented libxposed API 102 Adapted for Android 17 QPR1 Beta 4 Maintaince Postponed the planned deprecation of New XSharedPreferences in version 2.1.0 to 2.2.0. We strongly recommend migrating legacy modules to libxposed as soon as possible Feedback is now available by emailing to report@bug.lsposed.org Improved Significantly improved the performance of hooked methods Optimized invalidate inline hooks logic Optimized the mount logic of dex optimizer wrapper Optimized a range of UI experiences Fixed Fixed abnormal behavior of XposedBridge.unhookMethod Fixed a global detection point Fixed accessibility issues such as TalkBack repeating text and failing to read checked items https://lsposed.zip

LSPosed
190 393
Changes since latest release:
Added Provided high-speed CDN for the module repository. If you dislike ads, please switch to backup CDN in settings. Added SystemUI safe mode. Improved - Enhanced hook compatibility and performance - Improved homepage device name recognition. Fixed - Fixed Android 17 QPR1 Beta 3 crash issues - Fixed a series of M3E theme-related issues - Fixed Markdown WebView reload handling issues 自上次更新以来的改动: 新增 - 提供模块仓库高速 CDN,若不喜欢广告请在设置切换备用 CDN - 新增 SystemUI 安全模式 改进 - 提升 hook 兼容性和性能 - 增强首页设备名称识别 修复 - 修复 Android 17 QPR1 Beta 3 崩溃问题 - 修复一系列 M3E 主题相关问题 - 修复 Markdown WebView 重载处理问题

LSPosed
190 393
libxposed API 102 is now under RFC. Please give us suggestions regarding the API design. https://github.com/libxposed/api/pull/62

LSPosed
190 393
libxposed API 102 snapshots are now available. Open an issue on GitHub if you have any suggestion. Usage: add snapshot maven to settings.gradle.kts
maven {
    url = uri("https://central.sonatype.com/repository/maven-snapshots/")
    mavenContent {
        snapshotsOnly()
    }
    content {
        includeGroup("io.github.libxposed")
    }
}
Use snapshot builds:
compileOnly("io.github.libxposed:api:102.0.0-SNAPSHOT")
implementation("io.github.libxposed:service:102.0.0-SNAPSHOT")

LSPosed
190 393

LSPosed
190 393
kind reminder: you can also use lsposed.zip to download the latest public lsposed.

LSPosed
190 393
Repost from Magisk alpha
无法规避的Magisk识别方案已经公开:https://github.com/eltavine/Duck-Detector-Refactoring/pull/22 检测方法说明和概念验证app:https://github.com/LSPosed/DirtySepolicy

LSPosed
190 393
LSPosed-v2.0.2-7668-release.zip11.08 MB

LSPosed
190 393
LSPosed-v2.0.2-7668-release.zip11.08 MB

LSPosed
190 393
我们也同步发布了 libxposed 101.0.1 版本,带来了更详细的行为规范和开发文档。 We also released libxposed version 101.0.1, which brings more detailed behavior specifications and development documentation.

LSPosed
190 393
重大行为变更: - 基于 libxposed API 100 的模块已不再受支持,基于 rovo89 Xposed API 的模块不受影响 - 某些模块查询调用栈时硬编码深度(如 AnyWebView),责任链模式下调用栈将变深,可能超出模块查询长度导致功能异常,这是模块问题,请向模块作者反馈 - 某些模块通过查询调用栈等非正规方式判断框架实现(如 XChat),可能与框架冲突导致功能异常,这是模块问题,请向模块作者反馈 Major Behavioral Changes: - Modules based on libxposed API 100 are no longer supported. Modules based on the rovo89 Xposed API are not affected. - Some modules hardcode stack depth when inspecting the call stack, such as AnyWebView. In chain-of-responsibility mode, the call stack becomes deeper and may exceed the range expected by those modules, which can cause functionality issues. This is a module issue; please report it to the module author. - Some modules attempt to detect the framework implementation through unsupported methods such as call stack inspection, such as XChat. This may conflict with the framework and cause functionality issues. This is a module issue; please report it to the module author.

LSPosed
190 393
LSPosed-v2.0.1-7639-release.zip10.86 MB

LSPosed
190 393
Repost from N/a
LSPosed-v2.0.1-7639-release.zip10.86 MB

LSPosed
190 393
最期待API102实装哪些功能? What features are you most looking forward to seeing implemented in API 102?
Anonymous voting

LSPosed
190 393
libxposed API 101 has been released to the Maven Central Repository API 101 includes significant changes compared to API 82. We now only support API 82 and 101+, and other temporary solutions will be removed soon. JavaDoc: https://libxposed.github.io/api/ https://libxposed.github.io/service/