Android’s Verified Boot (VB) is a chain‑of‑trust mechanism that checks each stage of the boot process for tampering. When every component matches the cryptographic signatures stored by the device manufacturer, the boot state is reported as green. If a modification is detected – for example a custom recovery, an unlocked bootloader, or a modified system image – the state changes to yellow (unlocked but still verified) or red (failed verification). Knowing the current state helps you:
Because the verification result is stored in the bootloader, it survives a factory reset and even a full wipe of the internal storage. The only way to change the state is to unlock the bootloader or flash a non‑stock image.
Make sure you have a working USB connection and that the Android SDK Platform‑Tools are installed on your computer. You do not need root access, but you must enable USB debugging on the device.
C:\adb or ~/adb).If you see a dialog on the phone asking to allow USB debugging from this computer, tap Allow and optionally check “Always allow from this computer”.
ADB (Android Debug Bridge) can query the bootloader property that stores the verification state. The property name varies slightly between manufacturers, but the most common one is ro.boot.verifiedbootstate.
cd path/to/adbadb devices
You should see a line like xxxxxxxxxxxx device. If the state is unauthorized, re‑check the permission dialog on the phone.
adb shell getprop ro.boot.verifiedbootstate
The output will be one of the following:
When the result is green, you can be confident that the device’s integrity is intact. If you get yellow or red, consider the following:
yellow: The bootloader is unlocked. If you plan to keep the device stock, you can re‑lock the bootloader (see the “Re‑locking” section).red: A custom ROM, custom recovery, or a modified boot image is present. You may need to flash a stock image if you require a trusted state.Fastboot works when the device is in bootloader mode. It is useful for devices that hide the ADB property or for double‑checking the result.
fastboot devices
You should see a serial number. If not, reinstall the USB drivers (Windows) or ensure the fastboot binary is executable (Linux/macOS).
fastboot getvar unlocked
The output will be something like unlocked: yes or unlocked: no. While this tells you whether the bootloader is unlocked, it does not directly report the verification color. For that, use:
fastboot getvar verifysignature
Some devices return verifysignature: 1 (green) or 0 (red). If the variable is missing, fall back to the ADB method.
Starting with Android 12, Pixel devices expose a small UI hint in Developer Options.
This method is limited to stock Android and may be hidden on heavily skinned OEM ROMs. If you do not see the option, rely on ADB or fastboot.
greenYour device is in a trusted state. You can safely enable services that require integrity checks, such as:
No further action is required unless you plan to install a custom ROM.
yellowA yellow state means the bootloader is unlocked. The system image is still signed, but the device is considered less trustworthy by services that check the lock state.
Options:
green.
Re‑locking is only possible if the device is still running a stock image. Flashing a stock factory image first is recommended.
flash-all.sh or flash-all.bat) to restore stock partitions.fastboot flashing lock
Confirm the warning on the device (use volume keys to select “Yes”).
fastboot rebootWhen the device boots, repeat Method 1 to verify that the state is now green. Note that re‑locking will erase all data on some devices, so back up first.
redA red state indicates that the verification chain is broken – a custom boot image, a modified recovery, or a tampered system partition is present.
Typical reasons:
Solutions depend on your goal:
red state – many apps still work, but services that enforce SafetyNet may block you.getvar verifysignature as a cross‑check.Some OEMs expose a low‑level console when you connect via fastboot. The command fastboot oem device-info (Pixel) or fastboot getvar all can reveal additional flags:
fastboot oem device-info
[...]
Device unlocked: true
Device verified boot: true
Verified boot state: RED
Parsing these lines helps you script automated integrity checks for a fleet of devices.
Some manufacturers (e.g., Samsung) do not expose ro.boot.verifiedbootstate. In that case:
getvar unlocked to see if the bootloader is unlocked. A locked bootloader on Samsung usually means a green state.Ensure the fastboot binary is in your PATH or run it from the Platform‑Tools folder. On Windows, you may need to install the Google USB driver or use the adb.exe bundled driver.
Reasons include:
fastboot flashing lock_critical is required (Pixel 4a+). Use the fastboot flashing lock_critical command if the normal lock fails.In any case, back up data before attempting to lock, because the process may trigger a factory reset.
green state does not guarantee the OS is free of malware; it only guarantees the boot chain is intact. Continue using Play Protect, regular updates, and reputable app sources.adb shell getprop ro.boot.verifiedbootstate. Record the result.unknown, boot into fastboot and run fastboot getvar unlocked and fastboot getvar verifysignature.green state and have yellow or red, flash the official factory image and re‑lock the bootloader.green.| State | Bootloader | System Image | Typical Use‑Case |
|---|---|---|---|
| green | locked | stock, signed | Payments, SafetyNet, corporate MDM |
| yellow | unlocked | stock, signed | development, custom kernels (no ROM changes) |
| red | unlocked | custom or modified | custom ROMs, custom recoveries |
Verified Boot is a silent guardian that runs before Android even shows its UI. By learning how to read the boot state with ADB, fastboot, or the device UI, you gain a concrete metric of device integrity. Whether you’re a privacy‑conscious user, a developer preparing a test device, or an IT admin enforcing compliance, the steps in this guide let you verify the chain of trust, troubleshoot unexpected states, and safely return to a trusted green condition when needed.









