2026 Google Play Integrity API Verdicts & Magisk / KernelSU Audit Table
2026 Verified ReferenceGoogle Play Integrity API evaluates Android devices across three tiers: `MEETS_BASIC_INTEGRITY` (software environment check), `MEETS_DEVICE_INTEGRITY` (certified Android profile via Play Integrity Fix), and `MEETS_STRONG_INTEGRITY` (hardware-backed TEE Key Attestation verifying an untouched locked bootloader or valid non-revoked OEM keybox).
Verdict Tiers: BASIC_INTEGRITY → DEVICE_INTEGRITY (Google Pay/Wallet) → STRONG_INTEGRITY (Hardware Keybox)| Play Integrity Verdict / Vector | Hardware / OS Attestation Check | Root / Custom ROM Impact | Remediation / Hardening Architecture |
|---|---|---|---|
MEETS_BASIC_INTEGRITY | Software-level SafetyNet successor check | Fails if su binary or test-keys ro.build.tags exposed | Enable Zygisk Denylist / Shamiko or KernelSU Unmount |
MEETS_DEVICE_INTEGRITY | Play Protect certified fingerprint + DroidGuard check | Required by Google Wallet, NFC tap-to-pay & banking apps | Requires PlayIntegrityFix (PIF) valid certified print |
MEETS_STRONG_INTEGRITY | Hardware TEE / StrongBox KeyMaster certificate chain | Fails whenever bootloader is unlocked ( VerifiedBoot = Orange ) | Relock bootloader on stock signed ROM or TrickyStore |
| Zygisk & /proc/mounts Leak | Apps scan /proc/self/mounts for magisk/overlayfs strings | Triggers RASP (LIAPP / Promon / DexGuard) crash | Use KernelSU SusFS or Zygisk Assistant + Shamiko |
| ADB & Developer Options Check | Settings.Global.ADB_ENABLED == 1 detection | Fintech & UPI apps block login when USB Debug is ON | Turn off USB Debugging & hide mock location providers |
| Package Manager App List Scan | Queries installed packages for Magisk/LSPosed/Root apps | Detects default com.topjohnwu.magisk package name | Repackage manager with random stub + Hidemyapplist |
