Burning custom secure boot keys #8

Open
opened 2026-07-21 11:01:03 -04:00 by chipmunkmc · 0 comments
Owner

So I heard that many retail Exynos devices actually have unused keybanks (in the form of efuses) that one can install their own secure boot key to, and then be able to self-sign any bootloader they desire and boot it from internal storage (non-tethered).
Now I was linked one repository relating to burning keys (too lazy to find it rn), and I noticed it actually patches S-BOOT to call some functions (likely involving smcs) to do so from download mode.
Since osmium is a download mode exploit, perhaps it can pull this off? >:D

So I heard that many retail Exynos devices actually have unused keybanks (in the form of efuses) that one can install their own secure boot key to, and then be able to self-sign any bootloader they desire and boot it from internal storage (non-tethered). Now I was linked one repository relating to burning keys (too lazy to find it rn), and I noticed it actually patches S-BOOT to call some functions (likely involving `smc`s) to do so from download mode. Since osmium is a download mode exploit, perhaps it can pull this off? >:D
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
chipmunkmc/osmium#8
No description provided.