You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: brands/xiaomi/README.md
+89-56Lines changed: 89 additions & 56 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,93 +7,126 @@ In the past, Xiaomi allowed most of its devices to be unlocked after a period of
7
7
8
8
With the launch of Xiaomi's new Android fork, HyperOS, they have introduced a number of changes to the unlock process, with new device limits and Mi Account requirements.
9
9
10
-
Unisoc devices will never be unlockable, this is *not* Xiaomi's fault, Unisoc does not allow unlocking.
10
+
Unisoc devices will never be unlockable, this is *not* Xiaomi's fault, Unisoc does not allow unlocking.
11
11
12
-
## HyperOS
12
+
## Android One
13
13
14
-
It is currently **impossible** to officially unlock Xiaomi phones from the China region, especially if the device was imported and you are outside China. They have removed the unlocking function in their community app.
With HyperOS, Xiaomi introduced an additional step to the unlock process. You can make the request for unlocking the device inside Developer Options, only after you have made another separate successful request inside the Xiaomi Community App.
16
+
Devices shipping with Android One do NOT have any unlock requirements listed below. They follow the standard Android unlock process.
17
17
18
-
For the international verson you can request unlocking in their Community App at 00:00 Chinese GMT+8 time.
18
+
## Device unlock requirements
19
19
20
-
If [xiaomiui.net][global-requirements] is to be believed, the requirements for the Community App request are as follows:
21
-
* Your Mi Account has been active for more than 30 days.
22
-
* Xiaomi Community App version 5.3.31 or above.
23
-
*[As of January 1st, 2025][updated-policies], Xiaomi only let you unlock 1 device per year. This requirement has also been extended to MIUI 14.
20
+
Devices shipping with MIUI or HyperOS require activating your phone with Xiaomi servers before allowing unlocking. You can only unlock one phone in 30 days and four phones in a year.
24
21
25
-
Additionally, [on xda forums][community-app-cap] people have found that there is a cap on the amount of people (belived to be around 50 people) who can request per day inside the Community App, and it gets filled pretty much instantly, so your only chance to make a successful request there is if you get lucky spamming the request at midnight, Beijing time ([GMT+8][gmt+8]).
22
+
After enabling Developer options, go to Settings > Additional settings > Developer options, enable OEM Unlock and go to Device Unlock Status page, and if it shows "Locked" then you can proceed pressing "Add account and device" button to initiate the process.
26
23
27
-
### Workarounds
24
+
Doing these won't unlock your device immediately, but will grant you a permission to unlock in the end. So, to be able to eligible for unlocking, you will be asked to do these steps.
28
25
29
-
#### Snapdragon 8 Elite/8Gen3/8Gen2/8Gen1
26
+
Xiaomi will let you know what is required right now when you press "Add account and device", but to explain fully in order, it tells you to do:
30
27
31
-
All of those methods chain the QCOM SELinux bypass, and the Xiaomi MQSAS service privilege escalation vulnerabilities.
28
+
* Your device linked with a Xiaomi Account that is in a good standing (even better if it is not a recently created account)
29
+
* A SIM card inserted in with an active data plan (if device has SIM slot)
30
+
* Wi-Fi is disabled and mobile data is enabled (if device has SIM slot)
31
+
* If running HyperOS:
32
+
* See [new HyperOS requirements](#hyperos-specific) down below
32
33
33
-
- Xiaomi 17 series, POCO F8 Ultra, Redmi K90 Pro Max with Security Patch before February 2026: [XDA](https://xdaforums.com/t/xiaomi17-series-and-pocof8ultra-redmi-k90-pro-max-unlock-bootloader-xiaomi8elite5seriesbootloader-unlock.4781439/)
34
-
- Xiaomi 13, 14, 15 series, MIX Flip 2, Pad 8 Pro, Pad 6S Pro, Redmi K90/K80/K70/K60 Pro with Security Patch before January 2026: [XDA](https://xdaforums.com/t/guide-breakthrough-free-offline-bootloader-unlock-for-cn-xiaomi15-pro-ultra-redmi-k90-sd-8-elite-also-support-8g2-8g3-no-cn-exam-required.4786790/)
34
+
When you complete all above steps, pressing "Add account and device" button now should say "Added successfully" message.
35
35
36
-
It's theoretically possible to downgrade and unlock **non Kioxia UFS** devices using an EDL programmer and an engineering ABL: [XDA](https://xdaforums.com/t/unlock-bootloader-unbrick-xiaomi-8-elite-high-versions-auth-free-edl-firehose.4787466/)
36
+
To actually *perform* the unlocking, you will need to use [Mi Unlock][miunlock] tool for Windows and follow prompts to enter fastboot mode and connect your device. If you cannot or don't want to use official tool, you can also use alternative tools such as [offici5l][offici5l]'s [MiUnlockTool][py-miunlock] made in Python.
37
37
38
-
### Other
38
+
The unique key is to unlock the bootloader of your device is retrieved from Xiaomi servers, but there is a server-side (thus no tool can't bypass server time) countdown that will start running only after completing all steps above. For the most cases, the countdown is 3 days (= 72 hours) for HyperOS and 7 days (= 168 hours) for MIUI, but there are some reports people being forced to wait even more, such as 14 or 30 days instead.
39
39
40
-
*[AQLR][aqlr] The current bypass method, though you need to have your computer running at 00:00 Chinese ([GMT+8][gmt+8]) time. (The script is in AQLR.zip at the end of the post.)
41
-
***MlgmXyysd** - MlgmXyysd, the developer of the original bootloader bypass script, has discovered a new vulnerability in Qualcomm devices that enables bootloader unlocking on most HyperOS 2 and 3 phones. You may contact her on CoolAPK; according to some sources.
42
-
*~~Some users claim that visiting a Xiaomi store and asking a technician to downgrade the system version results in a temporary unlocked state. A few reported flashing their own system during this process.~~
43
-
*~~[HyperSploit][hypersploit] is the newer option. This is a simple to use program with no external dependencies.~~ Confirmed as patched as of HyperOS version 2.0.203.0. Still works on old versions.
44
-
*~~[Xiaomi-HyperOS-BootLoader-Bypass][xiaomi-hyperos-bootLoader-bypass] is the original proof of concept, but it's written in PHP and it's cumbersome to set up.~~ Same as above.
40
+
You can continue using your device as usual and check with the unlock tool anytime to see how much time is left. Meanwhile, DON'T remove your Xiaomi account or factory reset your phone, doing these may result in the countdown being reset to what it was initially.
41
+
42
+
> [!NOTE]
43
+
> For MIUI devices (not HyperOS), some channels on [Bilibili][bilibili-shutdown] claim that that Xiaomi verification server has been shutdown.
44
+
45
+
## HyperOS specific
45
46
46
-
At the very end of the unlock process, [offici5l][offici5l]'s Python [MiUnlockTool][py-MiUnlockTool] can be used instead of the official Windows only [Mi Unlock][MiUnlock].
47
+
It is currently **impossible** to officially unlock Xiaomi phones from the China region, especially if the device was imported and you are outside China. They have removed the unlocking function in their community app.
47
48
48
-
### Further Reading
49
+
With HyperOS, Xiaomi introduced an additional step to the unlock process. You can make the request for unlocking the device inside Developer Options, only after you have made another separate successful request inside the [Xiaomi Community App.][mi-community-app]
49
50
50
-
-[Xiaomi BootLoader Questionnaire Questions](https://github.com/MlgmXyysd/Xiaomi-BootLoader-Questionnaire) – community-collected notes and exam details.
51
+
For the international version you can request unlocking in their Community App at 00:00 Beijing (Chinese) [GMT+8][gmt+8] time.
51
52
52
-
## MIUI 14 and below
53
+
The [requirements for the Community App][global-requirements] request are as follows:
53
54
54
-
> [!NOTE]
55
-
>On [Bilibili](https://www.bilibili.com/video/BV15Ut2z5Epo/?spm_id_from=333.1387.search.video_card.click&vd_source=96eca9b96bc62dc161f76ff2ff1fc1f3) some channels claim that that Xiaomi verification server has been shutdown.
55
+
* Your Mi Account has been active for more than 30 days.
56
+
* Xiaomi Community App version 5.3.31 or above.
57
+
*[As of January 1st, 2025][updated-policies], Xiaomi only let you unlock 1 device per year. This requirement has also been extended to MIUI 14.
58
+
* Make sure to select "Global" region in Xiaomi Community app to see "Unlock bootloader" section under "Me" tab.
59
+
60
+
Additionally, [on XDA forums][community-app-cap] people have found that there is a cap on the amount of people (belived to be around 50 people) who can request per day inside the Community App, and it gets filled pretty much instantly, so your only chance to make a successful request there is if you get lucky spamming the request at midnight, Beijing time ([GMT+8][gmt+8]).
56
61
57
-
You should be able to use the "normal" unlock process, without the Community app.
62
+
There is a [AQLR][aqlr] (abbreviation of "application quota limit reached") script to do that automatically, so it would send a request to Xiaomi just before entering a new day in China, and you can have your computer running that script 7/24.
58
63
59
-
* Ensure a Xiaomi account was logged in on the device in the Settings app
60
-
* Go to Developer Options > Mi Unlock Status and press the button to request your device to be unlocked in the Xiaomi servers
61
-
* Then after 7+ days you can use the [official Mi Unlock][MiUnlock] for Windows or [offici5l][offici5l]'s Python [MiUnlockTool][py-MiUnlockTool] which will check those servers to see if a request has been made for that specific device and allow you to unlock it.
64
+
> [!WARNING]
65
+
> Even if it appears like you missed the today's quota, Xiaomi may report "application quota limit reached" [by a mistake even though you actually did placed in the quota][quota-error-problem]. So the only way is to be sure about that is to pressing "Add account and device" in Device Unlock Status page in Settings.
62
66
63
-
###Workarounds
67
+
## Workarounds & Exploits
64
68
65
-
EDL based unlock tool for Xiaomi Mi A1 and maybe all MSM89** manufactured before 2018:<br/>
All of those methods chain the QCOM SELinux bypass, and the Xiaomi MQSAS service privilege escalation vulnerabilities.
69
72
70
-
Look here if you want to learn about how Xiaomi's bootloader used to work: [Xiaomi-bootloader] <br/>
71
-
Alternative tools instead of Mi Flash Unlock: [Awesome Xiaomi BootLoader Unlock](https://github.com/topminipie/awesome-xiaomi-bootloader-unlock)
73
+
- Xiaomi 17 series, POCO F8 Ultra, Redmi K90 Pro Max with Security Patch before February 2026, [see here][xda-qcom-1]
74
+
- Xiaomi 13, 14, 15 series, MIX Flip 2, Pad 8 Pro, Pad 6S Pro, Redmi K90/K80/K70/K60 Pro with Security Patch before January 2026, [see here][xda-qcom-2]
72
75
76
+
It's theoretically possible to downgrade and unlock **non Kioxia UFS** devices [using an EDL programmer and an engineering ABL][firehose] too.
[EDLUnlock][edl-unlock], an EDL unlock tool for Xiaomi Mi A1 and maybe all MSM89xx manufactured before 2018.
81
+
82
+
### Others
83
+
84
+
***MlgmXyysd** - MlgmXyysd, the developer of the original bootloader bypass script, has discovered a new vulnerability in Qualcomm devices that enables bootloader unlocking on most HyperOS 2 and 3 phones. You may contact her on CoolAPK; according to some sources.
85
+
*~~Some users claim that visiting a Xiaomi store and asking a technician to downgrade the system version results in a temporary unlocked state. A few reported flashing their own system during this process.~~
86
+
*~~[HyperSploit][hypersploit] is the newer option. This is a simple to use program with no external dependencies.~~ Confirmed as patched as of HyperOS version 2.0.203.0. Still works on old versions.
87
+
*~~[Xiaomi-HyperOS-BootLoader-Bypass][xiaomi-hyperos-bootLoader-bypass] is the original proof of concept, but it's written in PHP and it's cumbersome to set up.~~ Same as above.
88
+
89
+
## Further reading
90
+
91
+
-[Xiaomi BootLoader Questionnaire Questions][bootloader-questionnaire] - community-collected notes and exam details.
-[Some research about the bootloader used in Xiaomi phones][xiaomi-bootloader]
94
+
95
+
And, Xiaomi's "reasoning" on [why they do this:][official-guide]
77
96
78
-
Devices shipping with Android One do NOT have any unlock requirements. They follow the standard Android unlock process.
97
+
> **Isn't locking the bootloader against Xiaomi's 'geek' spirit?**
98
+
>
99
+
> Locking the bootloader is aimed to provide a better user experience, which we've been trying to do the whole time. In the meantime, we've provided an unlocking tool for senior users who know their ways around flashing and tweaking their devices.
100
+
>
101
+
> The unlocking procedure will need internet access to get the unlocking password. Also, the Xiaomi Account logged in on the Xiaomi phone and the unlocking tool needs to be the same. Otherwise, the unlocking request will be denied. This will ensure that ill-intentioned people will not get access to your personal data.
79
102
80
103
***
81
-
Updated info provided by [n1ses](https://github.com/n1ses) & [Crimson Fork/🌌🏳️⚧️&ΘΔ](https://cf.spaceport.nexus) & [Mluo2011](https://github.com/Mluo2011) <br/>
104
+
Updated info provided by [n1ses](https://github.com/n1ses) & [Crimson Fork/🌌🏳️⚧️&ΘΔ](https://cf.spaceport.nexus) & [Mluo2011](https://github.com/Mluo2011)& [ysfchn](https://ysfchn.com)<br/>
0 commit comments