Bootloader Unlocking
   HOME

TheInfoList



OR:

Bootloader unlocking is the process of disabling the
bootloader A bootloader, also spelled as boot loader or called bootstrap loader, is a computer program that is responsible for booting a computer and booting an operating system. If it also provides an interactive menu with multiple boot choices then it's o ...
security that enforces secure boot during the boot procedure. It can allow advanced customizations possible, such as installing
custom firmware Custom firmware, also known as aftermarket firmware, is an unofficial new or modified version of firmware created by third parties on devices such as video game consoles, mobile phones, and various embedded system, embedded device types to provide ...
. On
smartphones A smartphone is a mobile phone with advanced computing capabilities. It typically has a touchscreen interface, allowing users to access a wide range of applications and services, such as web browsing, email, and social media, as well as mult ...
, this can be a custom Android distribution or another mobile
operating system An operating system (OS) is system software that manages computer hardware and software resources, and provides common daemon (computing), services for computer programs. Time-sharing operating systems scheduler (computing), schedule tasks for ...
. Some bootloaders are not locked at all and some are locked, but can be unlocked with a command, a setting or with assistance from the manufacturer. Some do not include an unlocking method and can only be unlocked through a software exploit. Bootloader unlocking is also done for mobile forensics purposes, to extract digital evidence from mobile devices, using tools such as Cellebrite UFED.


Background

Unlocking the bootloader allows installing and running unsigned code on a device, including user customized software. Operating outside the manufacturer specification might usually result in voiding any
warranties In law, a warranty is an expressed or implied promise or assurance of some kind. The term's meaning varies across legal subjects. In property law, it refers to a covenant by the grantor of a deed. In insurance law, it refers to a promise by the ...
and may make the device susceptible to data theft, as the integrity of the operating system (as intended by the manufacturer) can no longer be guaranteed. On Chromebooks, enabling developer mode makes the system less secure than a standard laptop running Linux. Unlocking the bootloader may require reinitialization, formatting to factory settings, or otherwise lead to data loss on Android and
ChromeOS ChromeOS, sometimes styled as chromeOS and formerly styled as Chrome OS, is an operating system designed and developed by Google. It is derived from the open-source operating system and uses the Google Chrome web browser as its principal user ...
devices. This is due to the fact that some user data is impossible to back up without root permission. This will also lead to certain security apps not working, such as Samsung Knox for which the counter would be stuck at "0x1." Sascha Segan from
PCMag ''PC Magazine'' (shortened as ''PCMag'') is an American computer magazine published by Ziff Davis. A print edition was published from 1982 to January 2009. Publication of online editions started in late 1994 and continues . Overview ''PC Magaz ...
considered a locked bootloader a mistake on the Qualcomm Snapdragon Insiders phone, which is targeted at advanced users.


Platforms


Android

Unlocking the bootloader is typically a prerequisite of obtaining ''root'' access and/or installing a custom ROM. **Unlocking Verizon Pixel bootloader


History

The bootloaders of
Nexus NEXUS is a joint Canada Border Services Agency and U.S. Customs and Border Protection-operated Trusted Traveler and expedited border control program designed for pre-approved, low-risk travelers. Members of the program can avoid waits at border ...
and
Pixel In digital imaging, a pixel (abbreviated px), pel, or picture element is the smallest addressable element in a Raster graphics, raster image, or the smallest addressable element in a dot matrix display device. In most digital display devices, p ...
devices can be unlocked by using the fastboot command fastboot oem unlock or if it doesn't recognize the command fastboot flashing unlock. When
Motorola Motorola, Inc. () was an American multinational telecommunications company based in Schaumburg, Illinois. It was founded by brothers Paul and Joseph Galvin in 1928 and had been named Motorola since 1947. Many of Motorola's products had been ...
released a bootloader unlocking tool for the Droid Razr,
Verizon Verizon Communications Inc. ( ), is an American telecommunications company headquartered in New York City. It is the world's second-largest telecommunications company by revenue and its mobile network is the largest wireless carrier in the ...
removed the tool from their models. In 2011,
Sony Ericsson Sony Mobile Communications Inc., originally Sony Ericsson Mobile Communications AB, was a Multinational corporation, multinational consumer electronics and telecommunications company, best known for its Mobile phones, mobile phone products. The ...
released an online bootloader unlocking tool. Sony requires the
IMEI The International Mobile Equipment Identity (IMEI) is a numeric identifier, usually Unique identifier, unique, for 3GPP and iDEN mobile phones, as well as some satellite phones. It is usually found printed inside the battery compartment of the ph ...
number to be filled in on their website. For the Asus Transformer Prime TF201, Asus has released a special bootloader unlock tool. In 2012, Motorola released a limited tool for unlocking bootloaders. They require accepting terms and conditions and creating an account before the bootloader can be unlocked for your Motorola device. A 2012 article by ''
The Verge ''The Verge'' is an American Technology journalism, technology news website headquarters, headquartered in Lower Manhattan, New York City and operated by Vox Media. The website publishes news, feature stories, guidebooks, product reviews, cons ...
'' called the unlockable bootloaders a 'broken promise' and called for a fix. HTC phones have an additional layer of lock called "S-OFF/S-ON". Bootloaders can be unlocked using an exploit or using a way that the vendor supplied. The latter method usually requires wiping all data on the device. In addition, some manufacturers prohibit unlocking on carrier locked phones. Although Samsung phones and cellular tablets sold in the US and Canada do not allow bootloader unlocks regardless of carrier status, a service has allowed users on an earlier version to unlock their US/Canadian Samsung phone(s) and/or tablet(s) In 2018, a developer from
XDA Developers Valnet, Inc. is a Canadian media company established in August 2012 by Hassan and Sam Youssef in Montreal, Quebec. It operates primarily in the entertainment media industry, where it has sought to acquire producers of content in this space. In ...
launched a service which allowed users to unlock the bootloader of some Nokia smartphone models. Similarly, another developer from
XDA Developers Valnet, Inc. is a Canadian media company established in August 2012 by Hassan and Sam Youssef in Montreal, Quebec. It operates primarily in the entertainment media industry, where it has sought to acquire producers of content in this space. In ...
launched a service to allow users to unlock the bootloaders of Samsung Galaxy S20 and Samsung Galaxy S21 Phones.
Huawei Huawei Technologies Co., Ltd. ("Huawei" sometimes stylized as "HUAWEI"; ; zh, c=华为, p= ) is a Chinese multinational corporationtechnology company in Longgang, Shenzhen, Longgang, Shenzhen, Guangdong. Its main product lines include teleco ...
announced plans to allow users to unlock the bootloader of the Mate 30 series, but later retracted that. Huawei has stopped providing bootloader unlock codes since 2018. A bootloader exploit named checkm30 has been developed for
HiSilicon HiSilicon ( zh, c=海思, p=Hǎisī) is a Chinese fabless semiconductor company based in Shenzhen, Guangdong province and wholly owned by Huawei. HiSilicon purchases licenses for CPU designs from ARM Holdings, including the ARM Cortex-A9 MPCore ...
based Huawei phones. When the bootloader of the Samsung Galaxy Z Fold 3 was unlocked, the camera became less functional. This could be restored by re-locking the bootloader. This issue was later fixed by Samsung. For the Samsung Galaxy S22 series, unlocking the bootloader has no effect on the camera.


Others


Microsoft

The WPInternals tool is able to unlock bootloaders of all Nokia Lumia phones running
Windows Phone Windows Phone (WP) is a discontinued mobile operating system developed by Microsoft Mobile for smartphones as the replacement successor to Windows Mobile and Zune. Windows Phone featured a new user interface derived from the Metro design languag ...
, but not phones like the
Alcatel Idol 4 Alcatel Idol 4 and Idol 4S are smartphones manufactured by TCL Corporation and marketed by Alcatel Mobile Phones. They were unveiled during Mobile World Congress in February 2016, and are a successor to the Idol 3. The Idol 4 and 4S are positione ...
or HP Elite x3. Version 1.0 was released in November 2015. In October 2018, the tool was released as open source software when the main developer René Lergner (also known as HeathCliff74) stepped down. The slab bootloader used by
Windows RT Windows RT is a mobile operating system developed by Microsoft and released alongside Windows 8 on October 26, 2012. It is a version of Windows 8 or Windows 8.1 built for the 32-bit ARM architecture (ARMv7), designed to take advantage of th ...
could be unlocked using a vulnerability, but was silently patched by Microsoft in 2016. UEFI Secure Boot on x86 systems can generally be unlocked.


Apple

The
boot ROM Boot ROM is a piece of read-only memory (ROM) that is used for booting a computer system. It contains instructions that are run after the CPU is reset to the reset vector, and it typically loads a bootloader. There are two types of boot ROM: ...
protection on iOS devices with an A11 processor or older can be bypassed with a hardware exploit known as checkm8, which makes it possible to run other operating systems including Linux. The bootloader on
Apple Silicon Apple silicon is a series of system on a chip (SoC) and system in a package (SiP) processors designed by Apple Inc., mainly using the ARM architecture family, ARM architecture. They are used in nearly all of the company's devices including Mac ...
-based Macs can be unlocked. However, other Apple devices like the
iPhone The iPhone is a line of smartphones developed and marketed by Apple that run iOS, the company's own mobile operating system. The first-generation iPhone was announced by then–Apple CEO and co-founder Steve Jobs on January 9, 2007, at ...
and
iPad The iPad is a brand of tablet computers developed and marketed by Apple Inc., Apple that run the company's mobile operating systems iOS and later iPadOS. The IPad (1st generation), first-generation iPad was introduced on January 27, 2010. ...
cannot be bootloader unlocked even when using the same chip used in a Mac.


Google

The equivalent of bootloader unlocking is called developer mode in
Chromebook Chromebook (sometimes stylized in lowercase as chromebook) is a line of laptops, desktops, tablets and all-in-one computers that run ChromeOS, a proprietary operating system developed by Google. Chromebooks are optimised for web access. They al ...
s. Chromebooks use custom bootloaders that can be modified or overwritten by removing a Write-protect screw. Some models lack a screw and instead may or may not require disabling the onboard Cr50 chi

In 2013, the bootloader of the
Chromecast Chromecast is a discontinued line of digital media players developed by Google. The devices, designed as small dongles, can play Internet-streaming media, streamed audio-visual content on a high-definition television or home audio system. The u ...
was hacked using an exploit. In 2021, it was hacked again for newer versions. In 2023, it was reported that the Chromecast HD could be unlocked without exploit.


Asus

Asus ASUSTeK Computer Inc. (, , , ; stylized as ASUSTeK or ASUS) is a Taiwanese Multinational corporation, multinational computer, phone hardware and electronics manufacturer headquartered in Beitou District, Taipei, Taiwan. Its products include deskto ...
used to provide an Unlocking tool for both of their smartphone lines, the Zenfone and ROG Phone. This worked as an installable .apk file that the user could install on their phone, then unlock the bootloader. The app worked by contacting Asus unlocking servers, then prompting the user to perform a factory reset. In 2023 Asus removed the tool from their website and closed the unlocking servers, so even phones with the .apk file installed couldn't unlock their bootloaders. Representatives on the Asus forums claimed the tool would be available again, but as of March 2024 no additional information has been provided, even after the release of their latest device the ROG Phone 8 and the upcoming release of the Zenfone 11 Ultra. A user on the popular forum XDA (website) filed a court claim application against Asus due to the unlock tool never being released and alleged that Asus censored comments about the unlock tool on their forum.


SpaceX

In August 2022, security researcher Lennert Wouters applied a voltage injection attack to bypass firmware verification of a
Starlink Starlink is a satellite internet constellation operated by Starlink Services, LLC, an international telecommunications provider that is a wholly owned subsidiary of American aerospace company SpaceX, providing coverage to around 130 countries ...
satellite dish from
SpaceX Space Exploration Technologies Corp., commonly referred to as SpaceX, is an America, American space technology company headquartered at the SpaceX Starbase, Starbase development site in Starbase, Texas. Since its founding in 2002, the compa ...
.


Relocking

After unlocking a bootloader, some devices allow users to relock it. Relocking is typically done to restore the device to a factory-like state, often for warranty purposes or to re-enable certain security features like verified boot. This process is usually carried out through fastboot commands or manufacturer-specific software. However, the ability to relock a bootloader varies significantly across manufacturers and device models. Some manufacturers provide official methods to relock the bootloader without issue, especially if the device is running official, signed firmware. In contrast, other devices may experience functionality issues after relocking—such as the loss of access to certain features or the risk of a "soft brick"—particularly if any system modifications remain or if unofficial firmware is installed. Importantly, relocking the bootloader does not always reverse all changes made during the unlocking process. For example, some devices will retain a bootloader unlock flag or record in the hardware's tamper logs, which may still void warranties or affect access to services like DRM-protected content. As a result, users are advised to consult manufacturer-specific guidelines and ensure that all system components are restored to their official state before attempting to relock the bootloader.


VNeID app changes

According to information from technology groups in Vietnam, after updating version 2.1.6 of the VNeID application released on May 30, 2024, some Android phone users have received warnings : "Your device is not safe, there is a risk of containing malicious code...". As a result, users are thrown to the main screen and cannot use the VNeID application, even though before the update they could still log in and use it normally. This is because VNeID 2.1.6 update has added new security measures to stop working on Android devices with root access, unlocked bootloader and developer mode enabled. To use, users must disable root access to the device, relock bootloader and turn off developer options.


Shutdown of online services

In 2018, Huawei stopped providing bootloader unlock codes. On 31 December 2021, LG shut down their website which provided bootloader unlock codes. In August 2023,
ASUS ASUSTeK Computer Inc. (, , , ; stylized as ASUSTeK or ASUS) is a Taiwanese Multinational corporation, multinational computer, phone hardware and electronics manufacturer headquartered in Beitou District, Taipei, Taiwan. Its products include deskto ...
removed the unlocking tool from their website and shut down the servers used to unlock the bootloader.


See also

* Booting process of Android devices *
Odin Odin (; from ) is a widely revered god in Norse mythology and Germanic paganism. Most surviving information on Odin comes from Norse mythology, but he figures prominently in the recorded history of Northern Europe. This includes the Roman Em ...
*


References


External links


Locking/Unlocking the Bootloader
Android Open Source Project Android is an operating system based on a modified version of the Linux kernel and other open-source software, designed primarily for touchscreen-based mobile devices such as smartphones and tablets. Android has historically been developed by ...

Qualcomm's Chain of Trust
{{DEFAULTSORT:Bootloader unlocking Android (operating system) Hardware restrictions Windows Phone IOS Microsoft Windows security technology Boot loaders