libxposed is now under RFC. We are planning the final version of the api, which is the last breaking change before publishing to MavenCentral. Please post issues if you have any suggestion or question.
See https://github.com/libxposed/api/pull/51
API level 100 won't be supported anymore after 101 releases, so please give us your idea to the draft in advance.
This means current new modules with API level 100 have to adapt to new API, or they will stop working.
libxposed API 101 has been released to the Maven Central Repository
API 101 includes significant changes compared to API 82. We now only support API 82 and 101+, and other temporary solutions will be removed soon.
JavaDoc:
https://libxposed.github.io/api/https://libxposed.github.io/service/
我们也同步发布了 libxposed api 101.0.1 版本,带来了更详细的行为规范和开发文档。
We also released libxposed api version 101.0.1, which brings more detailed behavior specifications and development documentation.
https://github.com/libxposed/api
Changes since last release:
Added
Enabled dynamic blur based on device state (e.g. power saving mode, performance class)
Added collapsing for long module descriptions
Added tapjacking mitigation toggle and hint
Hid the "install to other user" option when the module is already installed
Improved
Reduced per-method callback count to limit crash propagation caused by faulty modules
Ensured Xposed service is re-delivered after module updates
Sent binder to daemon earlier during system boot to reduce initialization race conditions
Removed the need to force stop when switching manager
Updated LSPlant to fix various injection issues
Updated MIUIX to address known issues
Optimized memory usage during manager startup and repository loading for low-RAM devices
Fixed
Fixed incorrect "install to user" behavior in the new manager
Fixed module configuration not being removed on uninstall
Fixed rare cases where hooks were not updated after module upgrade
Fixed native API loading timing for the new API
Fixed excessive memory usage during manager startup and repository loading
Fixed search results being obscured by the bottom bar
Fixed edge-to-edge layout issues in the new manager
新增
新管理器根据设备状态(如省电模式、性能等级)动态决定是否启用模糊效果
新管理器支持折叠过长的模块描述
新增点按劫持(tapjacking)缓解开关及提示
当模块已安装时,新管理器隐藏“安装到其他用户”的选项
改进
减少每个方法的最大回调数量,降低异常模块导致的系统崩溃扩散风险
确保模块更新后重新分发 Xposed 服务
系统启动阶段更早向 daemon 发送 binder,减少初始化竞态窗口
切换管理器无需再强行停止进程
更新 LSPlant,修复多类注入与 hook 相关问题
更新 MIUIX,修复已知兼容性问题
优化管理器启动及模块仓库加载时的内存占用
修复
修复新管理器“安装到用户”选项异常
修复卸载模块时未清理配置的问题
修复模块更新后在极少数情况下 hook 未生效的问题(如更新后立即强制停止目标应用)
修复新 API 的 native API 加载时机问题
修复管理器启动及加载模块仓库时的内存占用异常
修复搜索结果被底栏遮挡的问题(窗口 inset 处理)
修复新管理器边到边布局问题
v2.0.3 released:
Major Behavioral Changes
- Legacy modules are no longer allowed to call libxposed API; modules with targetApiVersion ≥ 102 will not be allowed to call legacy API; 101 modules are unaffected
New Features
- Introduced Material 3 Expressive style manager
- Enhanced theme-related settings to support dynamic color schemes and dark mode, and improved the display of cards, menus, bottom navigation, and dialogs
Improvements
- Improved log display and error logging; parsed view now correctly displays excessively long error stacks without fragmentation
- Attempted to improve hook performance
Fixes
- Fixed an issue where scope recommendations were displayed incorrectly in some legacy modules
- Fixed several issues with libxposed API implementations
Removals
- Removed the old MD3 manager
- Removed support for the 32-bit x86 architecture
v2.0.3 发布:
重大行为变更
- Legacy 模块不再允许调用 libxposed API;targetApiVersion ≥ 102 的模块不再允许调用 Legacy API,101 模块不受影响
新增
- 引入 Material 3 Expressive 风格管理器
- 完善主题相关设置,支持动态配色和深色模式,改进卡片、菜单、底部导航和对话框的显示效果
改进
- 改进日志显示和错误记录,现在解析视图能够正确显示超长错误栈而不被分片
- 尝试改进 hook 性能
修复
- 修复部分旧模块作用域推荐显示错误的问题
- 修复一些 libxposed API 实现问题
移除
- 移除旧的 MD3 管理器
- 移除 32 位 x86 架构支持
Download / 下载:
libxposed API 102 snapshots are now available. Join our internal test program to get LSPosed with API 102 support so you can test it. Please note that it's NOT final so NEVER use snapshots in production. Open an issue on GitHub if you have any suggestion.
Usage: add snapshot maven to settings.gradle.kts
maven {
url = uri("https://central.sonatype.com/repository/maven-snapshots/")
mavenContent {
snapshotsOnly()
}
content {
includeGroup("io.github.libxposed")
}
}
Use snapshot builds:
compileOnly("io.github.libxposed:api:102.0.0-SNAPSHOT")
implementation("io.github.libxposed:service:102.0.0-SNAPSHOT")
v2.1.0
新增
实现 libxposed API 102
适配 Android 17 QPR1 Beta 4
维护
原计划 2.1.0 废弃 New XSharedPreferences 推迟到 2.2.0,强烈建议 legacy 模块尽快迁移到 libxposed
改进
大幅提升被 hook 方法的性能
优化还原内联钩子逻辑
优化 dex 优化器包装的挂载逻辑
优化一系列的 UI 体验
修复
修复 XposedBridge.unhookMethod 行为异常
修复了一个全局检测点
修复 TalkBack 重复朗读、未朗读勾选状态等无障碍问题
Added
Implemented libxposed API 102
Adapted for Android 17 QPR1 Beta 4
Maintaince
Postponed the planned deprecation of New XSharedPreferences in version 2.1.0 to 2.2.0. We strongly recommend migrating legacy modules to libxposed as soon as possible
Improved
Significantly improved the performance of hooked methods
Optimized invalidate inline hooks logic
Optimized the mount logic of dex optimizer wrapper
Optimized a range of UI experiences
Fixed
Fixed abnormal behavior of XposedBridge.unhookMethod
Fixed a global detection point
Fixed accessibility issues such as TalkBack repeating text and failing to read checked items
下载 / Download
v2.1.1
新增
- 最低支持版本提升至 Android 9(API 28)
- 高级隐藏功能现可支持 A12+
- 允许一键清空已选作用域
改进
- 优化安全模式对 System UI 的检测阈值
- 恢复管理器中的模块数量徽标
- 改进错误报告发送流程
修复
- 修复部分情况下无法启动守护进程的问题
- 修复 XposedHelpers.findField API 行为
- 修复 Android 17 下服务连接接口不兼容的问题
- 修复模块详情页弹出菜单显示层级异常的问题
- 修复 Markdown 样式在部分页面中显示异常的问题
Added
- Raised the minimum supported version to Android 9 (API 28)
- Advanced hiding is now supported on Android 12 and above
- Added an option to clear all selected scope apps
Improved
- Optimized the System UI detection threshold in safe mode
- Restored the module count badge in the manager
- Improved the error report submission process
Fixed
- Fixed an issue that could prevent the daemon from starting
- Fixed the behavior of the XposedHelpers.findField API
- Fixed service connection incompatibility on Android 17
- Fixed incorrect popup menu layering on the module details page
- Fixed Markdown styles being displayed incorrectly on some pages
Видео VID_20260804_231937_915.mp4 · 11.0 МБ · нажмите — покажем
We discovered a privileged process arbitrary code execution vulnerability in Android 17. This vulnerability was patched in Android 17 QPR1 but was not included in any security bulletin. Combined with the dirty frag vulnerability (CVE-2026-43284), we achieved full root privilege escalation on Android 17.0.
The DirtyFrag vulnerability was disclosed 3 months ago but is still exploitabe, because Google has delayed the release frequency of vulnerability patches, changing from monthly to quarterly security bulletins. In the AI era, this behavior is completely incomprehensible. A large number of devices in the Android ecosystem are vulnerable to attacks due to the vulnerability details leaked in the Pixel system; even Pixel devices not participating in the beta program are not immune.
Therefore, we used two "already patched" vulnerabilities to demonstrate full rooting on Google Pixel 10 with the latest patches as a warning, urging Google to change its practices and release vulnerability patches promptly.
v2.2.0
重要
- New XSharedPreferences 计划于 2.3.0 正式移除,模块页面已为有兼容风险的模块加入废弃警告。判断逻辑为 legacy 模块声明支持 nsp 并存在 others 可读 xml。升级到 libxposed 或将 xposedminversion 设置为 82 并删除 xposedsharedprefs 以移除警告。
新增
- 支持注入 HyperOS Runtime 应用(需要兼容 Zygisk Next API 的 Zygisk 实现)
- 在 A17 及以上以注入方式处理 dex2oat 包装器,避免挂载泄漏(需要兼容 Zygisk Next API 的 Zygisk 实现)
改进
- 提升多进程应用中模块服务连接的稳定性
- 优化管理器中的兼容性状态展示与异常提示
修复
- 修复资源 Hook XML 重写长期失效的问题
- 修复模块热重载失败后可能产生状态异常的问题
- 修复 Hook 链调用及参数类型转换问题
- 修复系统框架在模块作用域中的排序
- 修复安全模式计数未在正常启动后重置的问题
- 修复 Dex 混淆及模块服务相关的内存泄漏
Important
- New XSharedPreferences is scheduled for official removal in version 2.3.0. Deprecation warnings have been added to the module page for modules at risk of compatibility issues. The probe logic identifies legacy modules that declare support for nsp and contain an XML file with others readable permission. To eliminate the warning, upgrade to libxposed or set xposedminversion to 82 and remove xposedsharedprefs.
Added
- Support for injecting into HyperOS Runtime apps (requires Zygisk implementation which is compatible with Zygisk Next API)
- Handles the dex2oat wrapper via injection on A17 and above to prevent mount leaks (requires Zygisk implementation which is compatible with Zygisk Next API)
Improved
- Improved stability of module service connections in multi-process apps
- Optimized the display of compatibility status and error prompts in the Manager
Fixed
- Fixed an issue where resource hook XML rewriting had been failing for an extended period
- Fixed an issue where a status exception might occur after a module hot reload failed
- Fixed issues with hook chain calls and parameter type conversions
- Fixed the sorting of the system framework within the module scope
- Fixed an issue where the safe mode count was not reset after a normal startup
- Fixed memory leaks related to DEX obfuscation and module services
Due to the increasing prevalence of AI and the accelerated submission of new modules, we plan to upgrade our module repository to an automated approval mode.
Following the approach of the Maven Central Repository, submitters will need to prove they control the domain name to which the module package name belongs. If there is no domain name, you can use io.github.[user name].[module name], which will automatically approve the submission. Other package names will generally not be approved.
This rule only applies to the approval of new modules and does not extend to existing modules, but we will begin checking whether the repository package name matches the released APK file.
由于AI普及,新模块提交加速,我们计划把模块仓库升级为自动审批模式。
仿照 Maven 中央仓库做法,提交者需要证明能控制模块包名所属的域名。如果没有域名,可以使用io.github.[user name].[module name],它会自动审批通过。其它包名原则上不会被批准。
该规则仅针对新模块审批,不溯及已有模块,但我们将开始检查仓库包名与发布的apk文件不符的情况。
libxposed future proposal: DexSQL
DexSQL lets you query Android DEX files with SQL, it replaces the DexParser that was deprecated in libxposed API 100.
It is now available for early access—feedback on slow or failing SQL statements is welcome.
libxposed 新功能提案:DexSQL
DexSQL 允许使用 SQL 语句查询 Android DEX 文件结构,它取代了libxposed API 100 中被废弃的DexParser。
现在可以抢先试用,欢迎反馈缓慢或者失败的SQL语句。
https://dexsql.lsposed.org/
The libxposed organization has been flagged by GitHub, to access the source code or java doc, you can download the relevant files from the Maven Central Repository.
libxposed 组织已被 GitHub 封锁,如需查阅源代码或文档,可在 maven 中央仓库下载相关文件。
https://repo.maven.apache.org/maven2/io/github/libxposed