Compare KernelSU and APatch: GKI kernel drivers versus KernelPatch inline binary patching, and what each means for root.
Core Architectural Difference in 30 Seconds
KernelSU is a native kernel driver integrated into the Generic Kernel Image (GKI) source code during compilation.
APatch is a binary patcher that injects KernelPatch routines directly into an existing, pre-compiled stock kernel image without requiring source code recompilation.
Head-to-Head Comparison: KernelSU vs. APatch
| Category | KernelSU | APatch |
|---|---|---|
| Implementation | Kernel Driver (Built into GKI kernel) | Binary Inline Patch (KernelPatch) |
| Kernel Range | Linux 5.10+ (GKI) or Custom Kernel | Linux 3.18 to 6.12 (Legacy & GKI) |
| Source Code Required | Yes (if compiling for non-GKI devices) | No (Patches pre-compiled stock boot.img) |
| Authentication | App Manager UI whitelist | SuperKey Master Hash Key |
| WebUI Modules | Yes (KernelSU WebUI Module standard) | Yes (APatch WebUI Module standard) |
Which Kernel-Level Root Should You Choose?
- Choose KernelSU if: You have a phone running GKI (Pixel 7/8/9, Galaxy S23/S24/S25, OnePlus 11/12/13) and want an official, standardized kernel driver.
- Choose APatch if: You have an older phone (Xiaomi Redmi Note 10, Galaxy S20, etc.) with a 4.14/4.19 kernel and want kernel-level root without hunting down custom kernels.
Explore More Root Comparisons & Guides
All Root Comparisons
Matrix HubCompare Magisk, KernelSU, APatch, and Shizuku across all architectural dimensions.
Download Magisk v30.7
Latest StableGet the latest official Magisk APK with Android 16 QPR2 and 16KB kernel support.
What is Zygisk?
ArchitectureLearn how Magisk in-process Zygote hooking works and why it remains the industry standard.
Last updated: September 23, 2026 • Checked against: Magisk v30.7, KernelSU v1.0+, APatch v10.7+, and Shizuku v13.5+.
Source Tree Compilation vs. Inline Kernel Patching
Both KernelSU and APatch provide kernel-level root privilege isolation, but they diverge radically in how they achieve kernel integration:
- KernelSU (Source / LKM Integration): Originally required compiling custom kernel source code with KSU drivers integrated into
fs/exec.canddrivers/. On modern Android 13+ devices, KernelSU GKI can be flashed as a precompiled Loadable Kernel Module (LKM), but device kernels must adhere strictly to Google's Generic Kernel Image ABI. - APatch (Inline Binary Patching via KernelPatch): APatch utilizes KernelPatch to patch the compiled
Imageorboot.imgbinary directly. It dynamically resolves kernel symbol addresses in the compiled ELF/raw kernel without requiring access to OEM source code, making it compatible with non-GKI legacy devices.
Security Credentials & SuperKey Protection
APatch introduces a unique security primitive known as SuperKey. During installation, the user configures a secret cryptographic passphrase. The kernel will only communicate with the APatch manager app if the client provides the valid SuperKey hash. Even if a malicious APK attempts to exploit the kernel interface, root privileges cannot be invoked without the user's secret key.
Choosing Between KernelSU and APatch
If your device runs Android 13 or higher with a modern GKI kernel (Linux 5.10, 5.15, 6.1, or 6.6), KernelSU offers greater developer adoption, official Next-branch modules, and standardized ABI support. If your device has an older, proprietary OEM kernel (Linux 4.14 or 4.19) where compiling a custom kernel is impractical, APatch is the superior kernel-level choice.