How to Extract boot.img From an OTA Zip or payload.bin
Get the stock boot.img or init_boot.img you need for rooting: which image to use, why the build must match, and how to extract it on the phone or on a computer.
Rooting by patching an image, whether with KernelSU’s LKM mode, APatch or Magisk, starts from your phone’s stock boot image. You patch it, then flash the result. The same stock image is also your way back: if the phone won’t boot, you flash the stock image again. (Since version 3.3.0, KernelSU’s manager can also download a full OTA or factory image by its address and patch it itself, so you may not need to extract anything. See KernelSU LKM vs GKI.)
Which image you need
boot.imgholds the kernel, and on older devices also the ramdisk.init_boot.imgexists on devices that launched with Android 13 or later. Android moved the generic ramdisk out ofbootinto this separate image.
Which one to patch depends on the root method:
| Root method | Image to patch |
|---|---|
| KernelSU, LKM mode | init_boot on devices that have it, otherwise boot |
| KernelSU, GKI mode | always boot, but KernelSU no longer supports GKI mode officially |
| APatch | always boot. Its guide says never to patch or flash init_boot |
| Magisk | init_boot if the device has one, otherwise boot; recovery on devices without a boot ramdisk |
Use the same build
Extract the image from the firmware build your phone is running. The build number is in Settings › About phone. That is our advice rather than a rule from the projects, which only say to use the official firmware, but a boot image from another build can fail to boot. On newer phones there is also anti-rollback protection: KernelSU’s guide warns that it can prevent flashing a boot image with an older security patch level.
Why there is a payload.bin
Many manufacturers ship updates as an OTA zip, with every partition image packed into a single payload.bin. Google’s full OTA for the Pixel 8, for example, is a zip of about 3.2 GB with payload.bin inside and no .img files. So you can’t just open the zip and take boot.img out; you need a tool that unpacks payload.bin.
Use a full OTA. An incremental OTA only contains binary patches to what is already on the phone, so it has no complete image to extract.
Option 1: extract on the phone
Payload Dumper does this on Android, no computer needed:
- Get the full OTA for your exact build. You can download the zip to the phone, or paste the OTA’s web address into the app: since version 5.0 it reads the payload over HTTP and downloads only the partitions you save. For the Pixel 8 OTA above, that is about 13 MB for
bootand 2 MB forinit_boot. This needs a server that allows partial downloads. - Open the OTA zip, or a
payload.binyou already have, in the app. - Tap Save next to
bootand/orinit_boot, or Save All. You can add more partitions while an extraction is running. - With Verify Hash on, which is the default, the app compares each extracted image with the SHA-256 in the payload. Don’t flash an image it marks as failed.
The files go to PayloadDumper in your internal storage, in a folder named after the time and the OTA. The app asks for all-files access because it has its own file browser and writes there. It marks the partitions of an incremental OTA with a red Incremental badge and doesn’t let you save them.
Option 2: extract on a computer
KernelSU’s guide points to payload-dumper-go, a command-line tool for Windows, macOS and Linux. It takes a payload.bin or the OTA zip itself:
payload-dumper-go -l ota.zip
payload-dumper-go -p boot,init_boot ota.zip
The first command lists the partitions, which also shows whether your device has init_boot. The second extracts only the images you need and checks their SHA-256 by default. Version 2.0 added support for incremental OTAs, but only on top of the images from the previous full OTA, so a full OTA is still the simpler starting point.
Some manufacturers make it easier
Some manufacturers publish full factory images with the partition images as separate files, so there is no payload.bin step. In Google’s factory images for Pixel phones, boot.img and init_boot.img are inside the nested image-<device>-<build>.zip. Check your manufacturer’s official firmware downloads before you reach for a dumper.
Next steps
- KernelSU: patch the image with the manager in LKM mode. See KernelSU LKM vs GKI.
- APatch: patch
boot.imgin the APatch app and set a strong SuperKey. - Compare all three root methods in KernelSU vs APatch vs Magisk.
Keep the stock image somewhere safe, off the phone. It is how you undo everything.
Apps in this guide
-
Payload Dumper Extracts boot.img and other partition images from an OTA zip or payload.bin on the phone, with hash verification.Download -
KernelSU The manager app for KernelSU, a root solution built into the Android kernel. It grants root per app and manages modules.Download -
APatch The manager for APatch, which roots Android by patching the kernel image and supports both Magisk-style and kernel modules.Download
Sources
- KernelSU installation guide (init_boot, anti-rollback, payload-dumper-go) checked Sep 30, 2026
- APatch installation guide (always patch boot.img) checked Sep 30, 2026
- Magisk installation guide (boot.img or init_boot.img) checked Sep 30, 2026
- Android generic boot partitions (init_boot on devices launching with Android 13) checked Sep 30, 2026
- Android OTA tools (full and incremental updates) checked Sep 30, 2026
- Payload Dumper for Android (README and releases) checked Sep 30, 2026
- payload-dumper-go (README) checked Sep 30, 2026
- Google factory images for Pixel devices checked Sep 30, 2026