SM-T827V (Verizon LTE) Tab S3 not rootable with current methods

Search This thread

snovvman

Senior Member
Jun 6, 2008
1,700
672
Not surprised and didn't expect it to work. There is also no OEM Unlock under Developer Options. I presume the bootloader is locked but haven't verified.
 
  • Like
Reactions: caizida123

iriman

Member
Oct 8, 2014
19
0
Not surprised and didn't expect it to work. There is also no OEM Unlock under Developer Options. I presume the bootloader is locked but haven't verified.

Yeah, have the US Cellular version sm-t827r4 with the exact same issue. Have had it since launch and have been hoping they'd enable the unlocker by now. Good luck!:laugh:
 

Dan Miller

Member
Feb 23, 2011
34
5
Neptune, NJ
I don't think anyone's even working on it. I have one too, and would love to see root, but I'm not a developer-wouldn't even know where to start. I also have a VZW Note 8 which has been rooted by the same methods that worked on the VZW S8. I believe that a variant on that method could work for our Tab S3s as well, but again, no clue how to begin.
 

elliwigy

Retired Forum Moderator / Recognized Developer
XDA App Taskforce
Well some progress today... I got the OEM lock switch flipped so both the prop values are set to 1:

[ro.oem_unlock_supported]: [1]
[sys.oem_unlock_allowed]: [1]

Somehow I also managed these to get set:

[ro.boot.verifiedbootstate]: [orange]
[ro.boot.flash.locked]: [0]

I am still trying to figure this one out:

[ro.boot.other.locked]: [1]

If someone who has a T825 or other tablet that is unlocked on stock can pull those prop values for me and let me know if I am on the right track then that would be great... I am still having trouble flashing anything customer in ODIN but with orange boot state I feel soon as we can get the img onto the device it should in theory boot.
 

Yliria

Member
Mar 7, 2018
15
1
Slowly learning root processes. Where is this build prop located and I'll check mine.

---------- Post added at 12:24 AM ---------- Previous post was at 12:06 AM ----------

Never mind. I'm a dingbat. I have the wrong model. I tried!
 

Sam Sung

Senior Member
Thanks for your efforts, ellwigy. If there's anything a novice can do to help with the process, let us know.

Also (to anyone): I think I can install a custom recovery (i.e., TWRP) even though unrooted so that a backup image of the device can be made? Is there a TWRP and guide for doing so? - Thx for any info!
 

suzook

Senior Member
Jan 25, 2010
4,475
1,177
Well some progress today... I got the OEM lock switch flipped so both the prop values are set to 1:

[ro.oem_unlock_supported]: [1]
[sys.oem_unlock_allowed]: [1]

Somehow I also managed these to get set:

[ro.boot.verifiedbootstate]: [orange]
[ro.boot.flash.locked]: [0]

I am still trying to figure this one out:

[ro.boot.other.locked]: [1]

If someone who has a T825 or other tablet that is unlocked on stock can pull those prop values for me and let me know if I am on the right track then that would be great... I am still having trouble flashing anything customer in ODIN but with orange boot state I feel soon as we can get the img onto the device it should in theory boot.
If you figure this out, think something similar would work for VZ tab s2?
 

ashyx

Inactive Recognized Contributor
Oct 14, 2012
15,055
9,947
Well some progress today... I got the OEM lock switch flipped so both the prop values are set to 1:

[ro.oem_unlock_supported]: [1]
[sys.oem_unlock_allowed]: [1]

Somehow I also managed these to get set:

[ro.boot.verifiedbootstate]: [orange]
[ro.boot.flash.locked]: [0]

I am still trying to figure this one out:

[ro.boot.other.locked]: [1]

If someone who has a T825 or other tablet that is unlocked on stock can pull those prop values for me and let me know if I am on the right track then that would be great... I am still having trouble flashing anything customer in ODIN but with orange boot state I feel soon as we can get the img onto the device it should in theory boot.
@elliwigy check this out, amazing stuff. Would never have believed it possible!

https://xdaforums.com/tab-s2/help/t818a-to-t818w-t3769853/
 
Well some progress today... I got the OEM lock switch flipped so both the prop values are set to 1:

[ro.oem_unlock_supported]: [1]
[sys.oem_unlock_allowed]: [1]

Somehow I also managed these to get set:

[ro.boot.verifiedbootstate]: [orange]
[ro.boot.flash.locked]: [0]

I am still trying to figure this one out:

[ro.boot.other.locked]: [1]

If someone who has a T825 or other tablet that is unlocked on stock can pull those prop values for me and let me know if I am on the right track then that would be great... I am still having trouble flashing anything customer in ODIN but with orange boot state I feel soon as we can get the img onto the device it should in theory boot.

I just got my T820 and rooted it. I'll pull those values when I get home.

Also if you want, I'm that guy from the Note 8 root group Ali on Telegram so you can also contact me there if you need anything.
 

Yliria

Member
Mar 7, 2018
15
1
Let's all just sit back and cross our fingers. If anyone can get that sucker cracked open, I'm sure it's Ellwigy. I've seen the magic they've done elsewhere on this site. I personally can't wait to stick a finger up at VZW and root mine.
 
Well some progress today... I got the OEM lock switch flipped so both the prop values are set to 1:

[ro.oem_unlock_supported]: [1]
[sys.oem_unlock_allowed]: [1]

Somehow I also managed these to get set:

[ro.boot.verifiedbootstate]: [orange]
[ro.boot.flash.locked]: [0]

I am still trying to figure this one out:

[ro.boot.other.locked]: [1]

If someone who has a T825 or other tablet that is unlocked on stock can pull those prop values for me and let me know if I am on the right track then that would be great... I am still having trouble flashing anything customer in ODIN but with orange boot state I feel soon as we can get the img onto the device it should in theory boot.

Here you go, my build.prop pulled straight from system.

SM-T820 running stock with Magisk v16 and force encryption disabled.
 

Attachments

  • build.zip
    3.6 KB · Views: 57

elliwigy

Retired Forum Moderator / Recognized Developer
XDA App Taskforce
  • Like
Reactions: Gccxen and Onclot

vaderyeh

Member
Aug 18, 2011
34
4
Would flashing Turkey's firmware "SM-T227" possibly work to achieve OEM unlock?
 
Last edited:

Top Liked Posts

  • There are no posts matching your filters.
  • 4
    Well some progress today... I got the OEM lock switch flipped so both the prop values are set to 1:

    [ro.oem_unlock_supported]: [1]
    [sys.oem_unlock_allowed]: [1]

    Somehow I also managed these to get set:

    [ro.boot.verifiedbootstate]: [orange]
    [ro.boot.flash.locked]: [0]

    I am still trying to figure this one out:

    [ro.boot.other.locked]: [1]

    If someone who has a T825 or other tablet that is unlocked on stock can pull those prop values for me and let me know if I am on the right track then that would be great... I am still having trouble flashing anything customer in ODIN but with orange boot state I feel soon as we can get the img onto the device it should in theory boot.
    3
    well, i just picked up atab s3 from vzw so ill b looking into it
    2
    @elliwigy check this out, amazing stuff. Would never have believed it possible!

    https://xdaforums.com/tab-s2/help/t818a-to-t818w-t3769853/

    heck if i can get root i can most likely boot twrp.. my verified boot state is orange which means i should (in theory) be able to boot with modified partitions.. ill try that tomorrow
    2
    Was that sent to you and how are they aware of the vulnerability?

    yes.. it was sent to me.. been goin back n forth with em a while now.. i submitted a report on it.. they have a rewards program.. theres some requirements such as certain devices, cant use leaked firmware etc. (must be legit exploits) which they pay between 200$ to 200k depending on severity and impact etc.

    i honestly was going to post it but at the time i seemed to b the only one with a t827v and the only one workin on root so i figured y not try n make some $$ off sammy lol.. plus i got rid of the tab s3..

    hadnt heard from em in over amonth so i was gonna say screw it but of course soon as i posted in here they responded lmao

    i signed an agreement anyways saying i wont release publicly until its patched..

    its a high severity (second from top which is critical) for excessive priveleges..

    pretty much pwnd it lol.. during my testing i rooted, semi unlocked bl, changed rev to 0 and downgraded to rev0 all without tripping knox lol
    1
    Not surprised and didn't expect it to work. There is also no OEM Unlock under Developer Options. I presume the bootloader is locked but haven't verified.