How to Extract boot.img From an OTA Zip or payload.bin

Get the stock boot.img or init_boot.img you need for rooting: which image to use, why the build must match, and how to extract it on the phone or on a computer.

Rooting by patching an image, whether with KernelSU’s LKM mode, APatch or Magisk, starts from your phone’s stock boot image. You patch it, then flash the result. The same stock image is also your way back: if the phone won’t boot, you flash the stock image again. (Since version 3.3.0, KernelSU’s manager can also download a full OTA or factory image by its address and patch it itself, so you may not need to extract anything. See KernelSU LKM vs GKI.)

Which image you need

  • boot.img holds the kernel, and on older devices also the ramdisk.
  • init_boot.img exists on devices that launched with Android 13 or later. Android moved the generic ramdisk out of boot into this separate image.

Which one to patch depends on the root method:

Root method Image to patch
KernelSU, LKM mode init_boot on devices that have it, otherwise boot
KernelSU, GKI mode always boot, but KernelSU no longer supports GKI mode officially
APatch always boot. Its guide says never to patch or flash init_boot
Magisk init_boot if the device has one, otherwise boot; recovery on devices without a boot ramdisk

Use the same build

Extract the image from the firmware build your phone is running. The build number is in Settings › About phone. That is our advice rather than a rule from the projects, which only say to use the official firmware, but a boot image from another build can fail to boot. On newer phones there is also anti-rollback protection: KernelSU’s guide warns that it can prevent flashing a boot image with an older security patch level.

Why there is a payload.bin

Many manufacturers ship updates as an OTA zip, with every partition image packed into a single payload.bin. Google’s full OTA for the Pixel 8, for example, is a zip of about 3.2 GB with payload.bin inside and no .img files. So you can’t just open the zip and take boot.img out; you need a tool that unpacks payload.bin.

Use a full OTA. An incremental OTA only contains binary patches to what is already on the phone, so it has no complete image to extract.

Option 1: extract on the phone

Payload Dumper does this on Android, no computer needed:

  1. Get the full OTA for your exact build. You can download the zip to the phone, or paste the OTA’s web address into the app: since version 5.0 it reads the payload over HTTP and downloads only the partitions you save. For the Pixel 8 OTA above, that is about 13 MB for boot and 2 MB for init_boot. This needs a server that allows partial downloads.
  2. Open the OTA zip, or a payload.bin you already have, in the app.
  3. Tap Save next to boot and/or init_boot, or Save All. You can add more partitions while an extraction is running.
  4. With Verify Hash on, which is the default, the app compares each extracted image with the SHA-256 in the payload. Don’t flash an image it marks as failed.

The files go to PayloadDumper in your internal storage, in a folder named after the time and the OTA. The app asks for all-files access because it has its own file browser and writes there. It marks the partitions of an incremental OTA with a red Incremental badge and doesn’t let you save them.

Option 2: extract on a computer

KernelSU’s guide points to payload-dumper-go, a command-line tool for Windows, macOS and Linux. It takes a payload.bin or the OTA zip itself:

payload-dumper-go -l ota.zip
payload-dumper-go -p boot,init_boot ota.zip

The first command lists the partitions, which also shows whether your device has init_boot. The second extracts only the images you need and checks their SHA-256 by default. Version 2.0 added support for incremental OTAs, but only on top of the images from the previous full OTA, so a full OTA is still the simpler starting point.

Some manufacturers make it easier

Some manufacturers publish full factory images with the partition images as separate files, so there is no payload.bin step. In Google’s factory images for Pixel phones, boot.img and init_boot.img are inside the nested image-<device>-<build>.zip. Check your manufacturer’s official firmware downloads before you reach for a dumper.

Next steps

Keep the stock image somewhere safe, off the phone. It is how you undo everything.

Apps in this guide

Sources