Bypass restrictions on non-SDK interfaces.
dexfile.Unsafe and setHiddenApiExemptions are stable APIs.Unsafe.HiddenApiBypass: Unsafe
LSPass: Property.of()
Google Play doesn't allow apps to use hidden APIs, reporting library usage will cause your app to fail app review, you need to disable dependencies info reporting in build.gradle. Remember to update this library to latest version to be compatible with new Android version.
android {
dependenciesInfo {
includeInApk = false
includeInBundle = false
}
}
repositories {
mavenCentral()
}
dependencies {
implementation 'org.lsposed.hiddenapibypass:hiddenapibypass:+'
}
This library has two variants of bypassing, they have the same API.
When initializing, LSPass is faster than HiddenApiBypass, but LSPass maybe blocked in future Android releases.
Replace HiddenApiBypass with LSPass if you do not want to use Unsafe.
HiddenApiBypass.invoke(ApplicationInfo.class, new ApplicationInfo(), "usesNonSdkApi"/*, args*/)
Object instance = HiddenApiBypass.newInstance(Class.forName("android.app.IActivityManager$Default")/*, args*/);
var allMethods = HiddenApiBypass.getDeclaredMethods(ApplicationInfo.class);
((Method).stream(allMethods).filter(e -> e.getName().equals("usesNonSdkApi")).findFirst().get()).invoke(new ApplicationInfo());
var allInstanceFields = HiddenApiBypass.getInstanceFields(ApplicationInfo.class);
((Method).stream(allInstanceFields).filter(e -> e.getName().equals("longVersionCode")).findFirst().get()).get(new ApplicationInfo());
var allStaticFields = HiddenApiBypass.getStaticFields(ApplicationInfo.class);
((Method).stream(allStaticFields).filter(e -> e.getName().equals("HIDDEN_API_ENFORCEMENT_DEFAULT")).findFirst().get()).get(null);
var ctor = HiddenApiBypass.getDeclaredConstructor(ClipDrawable.class /*, args */);
var method = HiddenApiBypass.getDeclaredMethod(ApplicationInfo.class, "getHiddenApiEnforcementPolicy" /*, args */);
HiddenApiBypass.addHiddenApiExemptions(
"Landroid/content/pm/ApplicationInfo;", // one specific class
"Ldalvik/system", // all classes in packages dalvik.system
"Lx" // all classes whose full name is started with x
);
if you are going to add all classes to exemption list, just leave an empty prefix:
HiddenApiBypass.setHiddenApiExemptions("");
Copyright 2021-2025 LSPosed
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
https://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
Java
100.0%
Bypass restrictions on non-SDK interfaces.
dexfile.Unsafe and setHiddenApiExemptions are stable APIs.Unsafe.HiddenApiBypass: Unsafe
LSPass: Property.of()
Google Play doesn't allow apps to use hidden APIs, reporting library usage will cause your app to fail app review, you need to disable dependencies info reporting in build.gradle. Remember to update this library to latest version to be compatible with new Android version.
android {
dependenciesInfo {
includeInApk = false
includeInBundle = false
}
}
repositories {
mavenCentral()
}
dependencies {
implementation 'org.lsposed.hiddenapibypass:hiddenapibypass:+'
}
This library has two variants of bypassing, they have the same API.
When initializing, LSPass is faster than HiddenApiBypass, but LSPass maybe blocked in future Android releases.
Replace HiddenApiBypass with LSPass if you do not want to use Unsafe.
HiddenApiBypass.invoke(ApplicationInfo.class, new ApplicationInfo(), "usesNonSdkApi"/*, args*/)
Object instance = HiddenApiBypass.newInstance(Class.forName("android.app.IActivityManager$Default")/*, args*/);
var allMethods = HiddenApiBypass.getDeclaredMethods(ApplicationInfo.class);
((Method).stream(allMethods).filter(e -> e.getName().equals("usesNonSdkApi")).findFirst().get()).invoke(new ApplicationInfo());
var allInstanceFields = HiddenApiBypass.getInstanceFields(ApplicationInfo.class);
((Method).stream(allInstanceFields).filter(e -> e.getName().equals("longVersionCode")).findFirst().get()).get(new ApplicationInfo());
var allStaticFields = HiddenApiBypass.getStaticFields(ApplicationInfo.class);
((Method).stream(allStaticFields).filter(e -> e.getName().equals("HIDDEN_API_ENFORCEMENT_DEFAULT")).findFirst().get()).get(null);
var ctor = HiddenApiBypass.getDeclaredConstructor(ClipDrawable.class /*, args */);
var method = HiddenApiBypass.getDeclaredMethod(ApplicationInfo.class, "getHiddenApiEnforcementPolicy" /*, args */);
HiddenApiBypass.addHiddenApiExemptions(
"Landroid/content/pm/ApplicationInfo;", // one specific class
"Ldalvik/system", // all classes in packages dalvik.system
"Lx" // all classes whose full name is started with x
);
if you are going to add all classes to exemption list, just leave an empty prefix:
HiddenApiBypass.setHiddenApiExemptions("");
Copyright 2021-2025 LSPosed
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
https://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
Java
100.0%