Please read the following before running anything in this repository!!!

September 28, 2025 · View on GitHub

Note

This is a fork of cheese by zhuowei and a re-implementation of critical vulnerability logged in Common Vulnerabilities and Exposures CVE-2025-21479 that Meta's security team failed to act up upon enabling us to perform root elevation in a white-hat way. The FreeXR project does not publish undisclosed vulnerabilities and follows ethical guidelines for security disclosures including cooperation with Meta Platform developers to improving the security of their products to manage abuse. Root does not make product abuse possible, it just makes it easier and this exploit affects the Eureka/Panther (Quest 3 and 3s) devices on "Meta Horizon OS" platform ever since it was released to the public. We only bring attention to this issue and publicly log them for further research.

Tip

Read the wiki. It has a lot of useful information on how to run the exploit without bricking your device, and how the exploit works as well :)

Note

If you are on a Pico 4 ultra, see the exploit from Mittron and zhuowei here

Caution

Using root on META Quest 3/3S is very dangerous as a SINGLE CHANGE IN THE BOOTLOADER PARTITION WILL RESULT IN A HARD BRICK AND MAKE YOUR DEVICE UNUSABLE!!! requiring one to unsolder the UFS chip and reprogramming it with external (and expensive) hardware. Reflashing the device via EDL is impossible due to Meta refusing to provide the users the cryptographical keys needed to authenticate secure boot on QFPROM implementation.

Basically, this means if you run a bad command, you can permanantly brick your device!!!

Warning

DO NOT USE THIS EXPLOIT UNLESS YOU KNOW WHAT YOU ARE DOING!

Warning

Pressing the INSTALL button in Magisk is going to brick your headset as it will make changes in the bootloader partitions! Never press that button!!!

Tip

Install the Magisk that is packaged in the releases. It will hide the INSTALL button. You can also grab a release from @VeygaX's official repository here.

Warning

Any change to the /system partition WILL RESULT IN HARD BRICK! again due to Meta refusing to provide the users the cryptographical keys.

Warning

Before you start make sure to backup your account's secrets - namely the deviceKey and your MetaProfileGenericAuthMap and Meta User ID. Refer to Our Private Quest setup guide for instructions. Without these secrets you won't be able to fully recover from soft-bricked headset.

Feel free to join our community and discuss how to use root safely, we also develop alternative operating system which utilizes root to perform the installation. NEVER INVOKE COMMANDS YOU ARE NOT 100% SURE WHAT THEY ARE DOING!!! IF YOU ARE UNSURE, RESEARCH OR JOIN OUR DISCORD

Warning

WE ARE NOT RESPONSIBLE FOR ANYTHING THAT HAPPENS TO YOUR DEVICE. BY DOWNLOADING, COMPILING, OR RUNNING THIS CODE, YOU AGREE THAT

  • YOU WILL ONLY USE IT ON DEVICES YOU OWN OR HAVE EXPLICIT PERMISSION TO USE ON
  • YOU ACKNOWLEDGE THAT USING EXPLOITS MAY BE ILLEGAL IN YOUR JURISDICTION
  • RUNNING THIS SOFTWARE MAY VOID YOUR DEVICE'S WARRANTY, CAUSE PERMANENT DAMAGE, OR RESULT IN DATA LOSS
  • THE AUTHORS AND CONTRIBUTORS ARE NOT LIABLE FOR ANY DAMAGES, WARRANTY VOIDING, DEVICE MALFUNCTION, OR LEGAL CONSEQUENCES
  • THIS SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED

Warning

IF YOU DO NOT AGREE TO THE ABOVE TERMS, DO NOT USE OR DISTRIBUTE THIS SOFTWARE

now let's get to the fun stuff :)


eureka_panther-adreno-gpu-exploit-1

An exploit using a memory corruption vulnerability in the Adreno GPU driver for Eureka/Panther (3/3s) devices, enabling arbitrary kernel memory read/write and privilege escalation.

Quest 3/3s Adreno GPU Root Exploit

Overview

This repository contains a full exploit chain for Meta Quest 3/3s devices (codenames: eureka/panther) leveraging a memory corruption vulnerability in the Adreno GPU driver (/dev/kgsl-3d0). The exploit achieves arbitrary kernel memory read/write, disables SELinux, and escalates privileges to root. It also includes a kernel dumper and kallsyms symbol resolver.

Tip

All information has now been moved to the Wiki! Go check it out here.


References

Thanks to everyone who helped with the development of the exploit! You all rock!!! -cats

reflection -cats

Thank you, everyone.

The FreeXR project began with something small - an issue I created on the QuestEscape repository. All I wanted was to use my Quest 3 as a Minecraft server for an upcoming LAN party with my friends and turn off the display to keep temperatures down - requiring root. At the time, my “arsenal” was just a MacBook Air M3 (16/256) and my school potato (i5-1135G7/8/256). On February 26th, I started the “Quest 3 Exploits” server.

Six months ago, I never could have imagined we’d be here today.

Now, half a year later, we’ve grown into a thriving community just shy of 1,000 members - developers, hardware hackers, everyday VR users (and cats!!), and we’ve developed a working root exploit for all Quest 3 and 3s devices (as of this writing).

In the process, I’ve been on a wild journey of learning and growth. The Quest 3 was my first Android device. I dove deeper into C while building the exploit. I’ve navigated the ups and downs of countless conversations in the server - from lighthearted jokes to heated debates, Mandi crashing out so hard in #remote-access-shell, Noah and I having massive headaches writing the FreeXR Discord Bot - and yes, even trolled Reddit...

Every challenge, every small victory, every connection I’ve made here has shaped me. I’ve met so many wonderful people, and each of you - whether you’ve stayed or moved on - has been part of this journey.

As an Australian teenager who had just stepped into the VR world when I opened that first GitHub issue, I never expected things to take off like this. But here we are - and I couldn’t be happier or prouder of what we’ve built together.

Thank you all. Here’s to whatever amazing things come next.

p.s. i never got a minecraft license, saving up for a Wooting 80HE 😤😤😤