A PoC that exploits a vulnerability to bypass the Xiaomi HyperOS community restrictions of BootLoader unlocked account bindings.
See the codeA PoC that exploits a vulnerability to bypass the Xiaomi HyperOS community restrictions of BootLoader unlocked account bindings.
Feel free pull request if you want :)
The project proudly uses the php-adb library.
✨ If you like my projects, you can buy me a coffee at:
After unlocking the BootLoader, you may encounter the following situations:
If you're experiencing any of the above, you should take all the responsibility yourself as this is the risk you may encounter when unlocking BootLoader. This obviously does not cover all risks. You've been warned.
If you're experiencing any of the above, consider yourself damned. Ever since Xiaomi restricted unlocking BootLoader, it has been against Xiaomi's 'geek' spirit and even the GPL. Xiaomi's restrictions on BootLoader unlocking are endless, and there's nothing we as developers can do about it.
A valid device:
A valid SIM card:
A valid Xiaomi account:
You have read and understood the Warning above.
* According to the unlocking instructions provided by Xiaomi, it will prohibit some accounts and devices from using the unlocking tool, which is called "risk control".
php.ini. (And/or set extension_dir to your PHP's ext directory if script not work.)adb.php in php-adb to the directory.libraries. Note: Mac OS needs to rename adb to adb-darwin.Settings - About Phone - MIUI Version to enable Development Options.OEM Unlocking, USB Debugging and USB Debugging (Security Settings) in Settings - Additional Settings - Development Options.Always allow from this computer and click OK.Find My Phone, and do not re-bind the device until it is successfully unlocked. The device will automatically send HeartBeat packets to the server every once in a while.Q: Why does the unlock tool still remind me to wait 168/360 (or more) hours?
Q: The device shows Couldn't verify, wait a minute or two and try again.
Q: Binding failed with error code 401.
Q: Binding failed with error code 20086.
Q: Binding failed with error code 20090 or 20091.
Q: Binding failed with error code 30001.
Q: Binding failed with error code 86015.
No license, you are only allowed to use this project. All copyright (and link, etc.) in this software is not allowed to be deleted or changed without permission. All rights are reserved by MeowCat Studio, Meow Mobile and NekoYuzu.
263 followers · starred Jul 2024
275 followers · starred Dec 2024
45 followers · starred Nov 2023
1,438 followers · starred Dec 2024
PHP
87.3%
Shell
12.7%
A PoC that exploits a vulnerability to bypass the Xiaomi HyperOS community restrictions of BootLoader unlocked account bindings.
See the codeA PoC that exploits a vulnerability to bypass the Xiaomi HyperOS community restrictions of BootLoader unlocked account bindings.
Feel free pull request if you want :)
The project proudly uses the php-adb library.
✨ If you like my projects, you can buy me a coffee at:
After unlocking the BootLoader, you may encounter the following situations:
If you're experiencing any of the above, you should take all the responsibility yourself as this is the risk you may encounter when unlocking BootLoader. This obviously does not cover all risks. You've been warned.
If you're experiencing any of the above, consider yourself damned. Ever since Xiaomi restricted unlocking BootLoader, it has been against Xiaomi's 'geek' spirit and even the GPL. Xiaomi's restrictions on BootLoader unlocking are endless, and there's nothing we as developers can do about it.
A valid device:
A valid SIM card:
A valid Xiaomi account:
You have read and understood the Warning above.
* According to the unlocking instructions provided by Xiaomi, it will prohibit some accounts and devices from using the unlocking tool, which is called "risk control".
php.ini. (And/or set extension_dir to your PHP's ext directory if script not work.)adb.php in php-adb to the directory.libraries. Note: Mac OS needs to rename adb to adb-darwin.Settings - About Phone - MIUI Version to enable Development Options.OEM Unlocking, USB Debugging and USB Debugging (Security Settings) in Settings - Additional Settings - Development Options.Always allow from this computer and click OK.Find My Phone, and do not re-bind the device until it is successfully unlocked. The device will automatically send HeartBeat packets to the server every once in a while.Q: Why does the unlock tool still remind me to wait 168/360 (or more) hours?
Q: The device shows Couldn't verify, wait a minute or two and try again.
Q: Binding failed with error code 401.
Q: Binding failed with error code 20086.
Q: Binding failed with error code 20090 or 20091.
Q: Binding failed with error code 30001.
Q: Binding failed with error code 86015.
No license, you are only allowed to use this project. All copyright (and link, etc.) in this software is not allowed to be deleted or changed without permission. All rights are reserved by MeowCat Studio, Meow Mobile and NekoYuzu.
263 followers · starred Jul 2024
275 followers · starred Dec 2024
45 followers · starred Nov 2023
1,438 followers · starred Dec 2024
PHP
87.3%
Shell
12.7%