Getting root rights on Xiaomi smartphones has traditionally been associated with unlocking the bootloader, a procedure that requires waiting, approval from the manufacturer and potential risks to warranty. However, there are workarounds to get extended rights without officially unlocking the bootloader. In this article, we will discuss all the current methods, their limitations and consequences for the device.
It's important to understand that none of these methods is 100% guaranteed to succeed. Xiaomi is actively closing vulnerabilities that previously could have been bypassed, so the performance of the methods depends on the device model, the firmware version. MIUI And we've analyzed the forums. 4PDA, XDA Developers and user reviews to gather the most up-to-date information for 2026.
If you're looking for a way to flash custom Recovery or install Magisk without unlocking, this is the guide for you, but first, let's look at why the manufacturer makes it so difficult, and what are the alternatives for those who are not willing to risk the stability of the system.
Why Xiaomi is blocking root without unlocking the bootloader
The manufacturer is imposing strict restrictions for a reason, and here are the key reasons why Xiaomi is making it harder to get root rights:
- ๐ Data security: Root access opens up opportunities for malware to gain control of system partitions, especially for supported devices MIUI Pay and other financial services.
- ๐ฑ Stability: Incorrect changes to system files often lead to โbricksโ (inoperable devices), which increases the burden on service centers.
- ๐ Controlling the ecosystem: Xiaomi is interested in keeping users in its ecosystem (e.g., using Mi Cloud or Mi Video.
- ๐ก๏ธ Warranty obligations: Any manipulation of the firmware will automatically void the warranty, even if the failure is not root related.
Since 2020, Xiaomi has tightened its policy to require a device-based Mi Account to be linked to the bootloader and wait up to 720 hours (30 days), making alternative methods even more popular, but most of them are based on exploits, firmware vulnerabilities that are patched over time.
โ ๏ธ Note: The methods described below may result in data loss, device locking, or inability to update. MIUI In the future, on devices with Dynamic. RAM Expansion root may disrupt this function.
Preparing the device: what to do before getting root
Before starting the procedure, follow the mandatory steps:
โ๏ธ Xiaomi Preparing for Root Without Unlocking
Pay special attention to the firmware version. For example, on the Xiaomi Redmi Note 10 Pro (sweet), the method using DirtyCow worked only on the device. MIUI 12.5.3. but ceased to function after the update to MIUI 13. Check the relevance of the method for your version:
| Xiaomi model | The Working Method (2026) | MIUI version | Notes |
|---|---|---|---|
| Redmi Note 9 Pro (joyeuse) | Exploit through CVE-2021-4034 | 12.0.8 โ 12.5.2 | Does not work on the Global-versions with the patch from 03.2023 |
| Poco X3 Pro (vayu) | Magisk in patched boot.img | 13.0.4 โ 13.0.6 | Requires a temporary loader unlock |
| Mi 11 Lite (renoir) | ADB-exploit | 12.5.5 โ 13.0.2 | It only works on EEA-firmware |
If your model is not listed in the table, check the thematic branches on the 4PDA or XDA by device code (e.g., alioth for Poco) F3). Note that some methods require a rollback on the old firmware, which can lead to the device locking due to antirollback.
๐ก
Before starting the procedure, disable all antiviruses on your PC โ they can block Magisk files or ADB, seeing them as a threat.
Method 1: Temporary root through DirtyCow vulnerability (for old firmware)
This method is based on exploit CVE-2021-4034 (It was known as DirtyPipe, which allowed temporary root access without unlocking the bootloader. 2022 It is currently supported on a limited number of models with outdated firmware.
Algorithm of action:
- Download the archive with the DirtyCow Root utility (check compatibility with your model).
- Connect your smartphone to your PC in Debugging mode USB (included in the settings โ The phone. โ Version. MIUI (7 times press) โ Additionally. โ For developers).
- Run the script. run-as-root.sh through ADB: adb push dirtycow /data/local/tmp/ adb shell chmod 777 /data/local/tmp/dirtycow adb shell /data/local/tmp/dirtycow
- If the exploit worked, you will get access to su for 1 session. Permanent root requires you to flash Magisk through temporary access.
โ ๏ธ Attention: On devices with MIUI 13+ This method doesn't work because of a vulnerability fix. Attempting to use it can lead to soft-brick).
If the script gives you a Permission Denied error, try:
- ๐ Reboot the device and repeat the process.
- ๐ฑ Install another version MIUI (For example, roll back 12.5 on the Fastboot).
- ๐ฅ๏ธ Launch. ADB on behalf of the administrator on the PC.
What to do if DirtyCow is not working?
Method 2: Installation of Magisk through patched boot.img (for some)
This method is suitable for devices where you can temporarily unlock the bootloader for one session (for example, through Fastboot with the Mi Account checkout bypass), it does not require constant unlocking, but still carries risks.
Instructions:
- Download the original boot.img for your firmware (you can extract from the official Fastboot-ROM via the Mi Flash Tool).
- Install Magisk Manager on your phone and patch it. boot.img via.
- Reboot the device in Fastboot (Battery) + Volume down) and flash the patch image: fastboot flash boot magisk_patched.img fastboot reboot
- If after the reboot there is a warning about damage to the bootloader, follow: fastboot --disable-verity --disable-verification flash vbmeta vbmeta.img fastboot reboot
This method works for Poco. X3 NFC (The surya, Redmi Note 8 Pro (begonia) and some other models, however, on new devices (such as Xiaomi 13 or Redmi Note 12), it is not applicable due to the increased protection. AVB 2.0.
| Advantages of the method | Deficiencies of the method |
|---|---|
| โ It does not require constant unlocking. | โ Does not work on all models |
| โ Compatible with Magisk and Modules | โ Risk of an anti-rollback trigger |
| โ You can roll back change. | โ Requires knowledge of working with ADB/Fastboot |
๐ก
If after the patching boot.img The device is not loading, try flashing the original boot.img back through Fastboot. 90% In some cases, it restores the workability.
Method 3: Using the Shamiko module to circumvent restrictions MIUI
Shamiko (formerly known as DenyList) is a module for Magisk that hides root from certain applications, including Xiaomi system services. It does not provide full root, but allows you to bypass some restrictions without unlocking the bootloader.
How to determine:
- Make sure that the device already has Magisk installed (for example, through temporary root or patched). boot.img).
- Download the Shamiko module and install it through Magisk Manager.
- Restart the device and open the module settings in Magisk.
- Add to the list of exceptions apps that should not see root (e.g. Mi Home, Mi Pay, Google Pay).
This method is suitable for:
- ๐ฒ Bypassing the lockdown of the installation APK source.
- ๐ง Use some root applications (e.g. Titanium Backup or Greenify).
- ๐ฎ Modifications of game parameters (for example, overclocking) GPU via Game Turbo).
โ ๏ธ Note: Shamiko does not allow access to system partitions /system or /vendor. For full root, you will still need to unlock the bootloader.
Root Alternatives: What You Can Do Without Unlocking the bootloader
If none of the methods worked, consider alternatives that donโt require root:
- ๐งน Removing Bloat Without Root: Use ADB Deactivation of system applications: adb shell pm uninstall -k --user 0 com.miui.analytics (a complete list of removal packages can be found at 4PDA).
- ๐ง Change of change DNS: To block advertising in MIUI set up privately DNS In Settings โ Connections โ Private DNS (e.g. dns.adguard.com).
- ๐ฑ Shizuku: This tool allows some applications (like App Ops) to gain rights ADB rootless.
- ๐ Castom launchers: Install Nova Launcher or Hyperion to change the interface without interfering with the system.
For devices on MIUI 14+ The "Developer Mode" function is also available, which allows:
- Disable animations (Settings) โ Additionally. โ For developers โ Scale of animation).
- Turn on the debugging. USB for scrcpy (managing phone with PC).
- Configure the limitations of background processes.
๐ก
If you need root only to remove ads in the MIUI, Try to disable personalized ads in your Mi Account settings. This reduces the number of banners on your account. 60-70%.
Risks and how to minimize them
Any method of getting root without unlocking the bootloader comes with risks, and here are the most common problems and ways to avoid them:
| Risk | Effects of consequences | How to minimize |
|---|---|---|
| Soft-brick (cyclical download) | The device is switched on but not loaded beyond the logo | Use only verified patches for your model |
| Hard-brick (full lock) | The device does not respond to buttons, is not determined by the PC | Don't stitch incompatible boot.img or vbmeta |
| Loss of loss OTA-update | The system stops receiving updates over the air | Before upgrading, remove Magisk and restore the original boot |
| Blocking Mi Accounts | Accounts may be blocked for suspicious activity | Do not use one account on multiple root devices |
If the device has stopped loading:
- Try to boot up in Fastboot (Loudness Down). + Food) and to sew the original boot.img.
- If it doesnโt work, use the Mi Flash Tool for full flashing (select the Clean All option).
- On some models, resetting through Recovery (Loudness up) helps. + Nutrition โ Wipe Data).
Remember: Xiaomi can remotely block devices with unofficial modifications through the Mi Cloud service. If after receiving root, the phone is no longer identified in Find My Device, this may be the first sign of future lock.