KernelSU vs APatch vs Magisk: Which Root Solution Fits Your Phone (2026)

KernelSU and APatch root Android from the kernel; Magisk patches the boot image. Kernel support, modules and requirements compared, with APKs checked.

There are three main ways to root a modern Android phone. Magisk patches the boot image and has been the standard for years. KernelSU and APatch move root into the kernel itself. All three need an unlocked bootloader and your phone’s stock boot image, and all three can be undone by flashing that image back.

All three are open source, and we host all three. KernelSU and APatch come through IzzyOnDroid. Magisk is its official GitHub release, the only download source its developer calls official (F-Droid also builds it from source).

Quick picks

  • Your phone launched with Android 12 or later and has a GKI kernel: KernelSU is the most direct choice. It is designed for exactly these kernels.
  • Your kernel is older than 5.10 but at least 3.18, and the phone is ARM64: APatch covers that range without you having to build a kernel. The trade-off is the SuperKey, a password with more power than root. Choose a strong one.
  • You depend on a specific Magisk module, or want the widest device support: Magisk remains the standard choice. Its page walks through the official install steps.

Side by side

KernelSU APatch Magisk
Where root lives In the kernel In the patched kernel image (KernelPatch) Patched boot image, user space
Kernel support GKI 2.0 (5.10+) officially; 4.14+ if you build the kernel 3.18 to 6.1 Almost any
CPU arm64, x86_64 arm64 only arm, arm64, x86, x86_64
Modules OverlayFS-based, Magisk-like APM (Magisk-like) plus KPM kernel modules Magisk modules
Who can see su Only apps you grant Only apps you grant Configurable (DenyList)
Extra secret to manage No Yes, the SuperKey No
Manager app needs Android 12+ Android 8.0+ Android 6.0+

The CPU and Android-version rows come from the APKs we host. The rest comes from each project’s documentation.

The step all three share: get your boot image

Every method starts with the stock boot.img (or init_boot.img on phones that launched with Android 13 or later) for the exact firmware you are running. If your manufacturer only ships OTA zips, Payload Dumper extracts the image on the phone, with hash verification, and no computer is needed.

Keep that stock image somewhere safe. Flashing it back is how you get out of a boot loop, whichever root method you chose.

How we checked these apps

We matched KernelSU, APatch and Payload Dumper to the signing keys IzzyOnDroid publishes for them, and Magisk to the hash GitHub publishes for its release and to its developer’s certificate. We scanned all four against the Exodus Privacy tracker list, and none contains tracker code. KernelSU asks for one runtime permission (notifications). APatch asks only for storage. Payload Dumper needs all-files access to read OTA zips. The full results are on each app’s page.

Download the 4 apps

Popular Topics