Kaeru is a powerful tool that provides arbitrary code execution on MediaTek bootloaders.
What does it do for you?
Kaeru can spoof the LK (Little Kernel) bootloader state, making your device report itself as locked. This can help achieve a locked-bootloader state for certain integrity checks without the usual hassle. (More on that in their GitHub.)
⚠️ N.B: This will only work on S Vendor.
Click here to download
Changelog
Added vbmeta state spoof.
How to use?
Before starting, disable all GMS spoofing.
1. Boot your device into Fastboot Mode.
2. Flash the Kaeru image:
fastboot flash lk kaeru.bin
3. Reboot back into Fastboot Mode.
4. Enable bootloader spoof:
fastboot oem bldr_spoof on
5. If you are using anything other than MIUI, flash @creativchic 's disabled vbmeta files (This prevents the device from rebooting back into the bootloader)
6. Reboot to system. The unlocked bootloader warning will disappear.
7. Use the Play Integrity Fix module to pass Strong Integrity.
That's all! 🎉
A huge thank you to Roger for providing the Merlin Kaeru reference and helping drive this mission forward, and to @creativchic for the disabled vbmeta files. ❤️
Join: @Redmi10_Updates
Follow: @Redmi10_Community
















