How to Verify Android’s Verified Boot Status

14 min read Learn how to check your Android device’s Verified Boot state using ADB, fastboot, and built‑in settings, with troubleshooting tips for common issues. September 27, 2026 16:00 How to Verify Android’s Verified Boot Status

Why Verified Boot Matters

Android’s Verified Boot (VB) is a chain‑of‑trust mechanism that checks each stage of the boot process for tampering. When every component matches the cryptographic signatures stored by the device manufacturer, the boot state is reported as green. If a modification is detected – for example a custom recovery, an unlocked bootloader, or a modified system image – the state changes to yellow (unlocked but still verified) or red (failed verification). Knowing the current state helps you:

  • Confirm that your device hasn’t been compromised by malware that replaces boot files.
  • Validate that a recent OTA update was applied correctly.
  • Decide whether you can safely enable features that require a trusted device, such as mobile payments (Google Pay) or corporate device‑management policies.

Because the verification result is stored in the bootloader, it survives a factory reset and even a full wipe of the internal storage. The only way to change the state is to unlock the bootloader or flash a non‑stock image.

Before You Start

Make sure you have a working USB connection and that the Android SDK Platform‑Tools are installed on your computer. You do not need root access, but you must enable USB debugging on the device.

  1. Download the latest Platform‑Tools zip for your OS.
  2. Extract the zip to a convenient folder (e.g., C:\adb or ~/adb).
  3. On the Android device, open Settings → About phone → tap Build number seven times to enable Developer Options.
  4. Return to Settings → System → Developer options → enable USB debugging. If a prompt appears, grant permission.
  5. Connect the phone to the computer with a good quality USB‑C or micro‑USB cable. Choose “File Transfer” or “Charging only” – the mode does not affect ADB.

If you see a dialog on the phone asking to allow USB debugging from this computer, tap Allow and optionally check “Always allow from this computer”.

Method 1 – Checking Verified Boot via ADB

ADB (Android Debug Bridge) can query the bootloader property that stores the verification state. The property name varies slightly between manufacturers, but the most common one is ro.boot.verifiedbootstate.

  1. Open a terminal (Command Prompt, PowerShell, or a Linux shell) and navigate to the Platform‑Tools folder.
    cd path/to/adb
  2. Confirm the device is detected:
    adb devices

    You should see a line like xxxxxxxxxxxx device. If the state is unauthorized, re‑check the permission dialog on the phone.

  3. Run the following command to read the property:
    adb shell getprop ro.boot.verifiedbootstate

    The output will be one of the following:

    • green – The device is running a fully verified, stock boot image.
    • yellow – The bootloader is unlocked, but the boot image is still signed (common on devices that allow unlocking without flashing custom images).
    • red – Verification failed – a custom image or tampered boot component is present.
    • unknown – Some OEMs hide the property; you’ll need an alternative method.

When the result is green, you can be confident that the device’s integrity is intact. If you get yellow or red, consider the following:

  • yellow: The bootloader is unlocked. If you plan to keep the device stock, you can re‑lock the bootloader (see the “Re‑locking” section).
  • red: A custom ROM, custom recovery, or a modified boot image is present. You may need to flash a stock image if you require a trusted state.

Method 2 – Using Fastboot to Read the Boot State

Fastboot works when the device is in bootloader mode. It is useful for devices that hide the ADB property or for double‑checking the result.

  1. Power off the device completely.
  2. Enter fastboot mode. The key combination varies:
    • Pixel / Nexus: Hold Power + Volume Down.
    • Samsung (most models): Hold Power + Volume Up + Bixby (or just Power + Volume Up on newer devices).
    • OnePlus: Hold Power + Volume Up.
  3. Connect the phone to the computer via USB.
  4. In the terminal, verify the connection:
    fastboot devices

    You should see a serial number. If not, reinstall the USB drivers (Windows) or ensure the fastboot binary is executable (Linux/macOS).

  5. Run the command to query the lock state:
    fastboot getvar unlocked

    The output will be something like unlocked: yes or unlocked: no. While this tells you whether the bootloader is unlocked, it does not directly report the verification color. For that, use:

    fastboot getvar verifysignature

    Some devices return verifysignature: 1 (green) or 0 (red). If the variable is missing, fall back to the ADB method.

Method 3 – Checking the Status from the Device UI (Pixel & Android 12+)

Starting with Android 12, Pixel devices expose a small UI hint in Developer Options.

  1. Open Settings → System → Developer options.
  2. Scroll to the Verification section. You will see a line reading Verified boot state: Green / Yellow / Red.

This method is limited to stock Android and may be hidden on heavily skinned OEM ROMs. If you do not see the option, rely on ADB or fastboot.

Interpreting the Results – What to Do Next

Result: green

Your device is in a trusted state. You can safely enable services that require integrity checks, such as:

  • Google Pay and other NFC payment apps.
  • Enterprise Mobile Device Management (MDM) policies that enforce a “trusted device”.
  • SafetyNet‑based apps (e.g., Netflix, banking apps).

No further action is required unless you plan to install a custom ROM.

Result: yellow

A yellow state means the bootloader is unlocked. The system image is still signed, but the device is considered less trustworthy by services that check the lock state.

Options:

  1. Re‑lock the bootloader (if you have not flashed any custom images). This will return the state to green.
  2. Continue with unlocked bootloader if you need it for development, but be aware that some apps may refuse to run.

How to Re‑lock the Bootloader

Re‑locking is only possible if the device is still running a stock image. Flashing a stock factory image first is recommended.

  1. Download the official factory image for your device from the manufacturer’s site (Pixel, OnePlus, etc.).
  2. Extract the archive and open a terminal in the extracted folder.
  3. Boot the device into fastboot mode (see Method 2).
  4. Run the flash script (e.g., flash-all.sh or flash-all.bat) to restore stock partitions.
  5. After flashing completes, issue the lock command:
    fastboot flashing lock

    Confirm the warning on the device (use volume keys to select “Yes”).

  6. Reboot:
    fastboot reboot

When the device boots, repeat Method 1 to verify that the state is now green. Note that re‑locking will erase all data on some devices, so back up first.

Result: red

A red state indicates that the verification chain is broken – a custom boot image, a modified recovery, or a tampered system partition is present.

Typical reasons:

  • Custom ROM (LineageOS, Pixel Experience, etc.).
  • Custom recovery (TWRP, OrangeFox) installed while the bootloader remains unlocked.
  • Partial OTA that failed and left a mismatched signature.

Solutions depend on your goal:

  1. If you need a trusted device, flash the official factory image for your exact model and then re‑lock the bootloader (see the re‑locking steps above).
  2. If you are comfortable with a custom ROM, accept the red state – many apps still work, but services that enforce SafetyNet may block you.
  3. If the state appears red unexpectedly, it may be a false positive caused by a manufacturer that hides the property. Use fastboot getvar verifysignature as a cross‑check.

Advanced Checks – Using the Bootloader Console

Some OEMs expose a low‑level console when you connect via fastboot. The command fastboot oem device-info (Pixel) or fastboot getvar all can reveal additional flags:

fastboot oem device-info

[...]
Device unlocked: true
Device verified boot: true
Verified boot state: RED

Parsing these lines helps you script automated integrity checks for a fleet of devices.

Troubleshooting Common Issues

ADB Returns “unknown” or No Property

Some manufacturers (e.g., Samsung) do not expose ro.boot.verifiedbootstate. In that case:

  • Use fastboot getvar unlocked to see if the bootloader is unlocked. A locked bootloader on Samsung usually means a green state.
  • Check the “Device integrity” entry in Settings → Biometrics & security → Device integrity. Samsung shows “Google Play Protect certification” which correlates with a green state.

Fastboot Not Recognized

Ensure the fastboot binary is in your PATH or run it from the Platform‑Tools folder. On Windows, you may need to install the Google USB driver or use the adb.exe bundled driver.

Device Refuses to Re‑lock

Reasons include:

  • Bootloader is already locked – the command will return “already locked”.
  • Device is running a custom image – many manufacturers block re‑locking until a stock image is flashed.
  • OEM‑specific flag fastboot flashing lock_critical is required (Pixel 4a+). Use the fastboot flashing lock_critical command if the normal lock fails.

In any case, back up data before attempting to lock, because the process may trigger a factory reset.

Safety and Privacy Considerations

  • Data loss: Re‑locking the bootloader on many devices triggers a factory reset. Back up everything (photos, SMS, app data) before proceeding.
  • Warranty: Unlocking the bootloader often voids the manufacturer’s warranty. If you re‑lock with a stock image, some manufacturers still consider the device “previously unlocked”. Check your warranty policy.
  • Security: A green state does not guarantee the OS is free of malware; it only guarantees the boot chain is intact. Continue using Play Protect, regular updates, and reputable app sources.

Putting It All Together – A Quick Checklist

  1. Enable USB debugging and connect the device.
  2. Run adb shell getprop ro.boot.verifiedbootstate. Record the result.
  3. If the result is unknown, boot into fastboot and run fastboot getvar unlocked and fastboot getvar verifysignature.
  4. Compare the output with the table below to determine trust level.
  5. If you need a green state and have yellow or red, flash the official factory image and re‑lock the bootloader.
  6. Verify again with ADB to confirm the state is now green.
StateBootloaderSystem ImageTypical Use‑Case
greenlockedstock, signedPayments, SafetyNet, corporate MDM
yellowunlockedstock, signeddevelopment, custom kernels (no ROM changes)
redunlockedcustom or modifiedcustom ROMs, custom recoveries

Conclusion

Verified Boot is a silent guardian that runs before Android even shows its UI. By learning how to read the boot state with ADB, fastboot, or the device UI, you gain a concrete metric of device integrity. Whether you’re a privacy‑conscious user, a developer preparing a test device, or an IT admin enforcing compliance, the steps in this guide let you verify the chain of trust, troubleshoot unexpected states, and safely return to a trusted green condition when needed.

User Comments (0)

Add Comment
We'll never share your email with anyone else.