Zalo Patch

Zalo Patch is an open-source LSPosed module for customizing Zalo while keeping compatibility fail-soft and exact-version based.

Compatibility

  • Zalo package: com.zing.zalo
  • Supported builds: Zalo 26.10.01 (versionCode 261001903 or 261001905)
  • Android 8.0 (API 26) or newer
  • LibXposed API 102

Unsupported Zalo artifacts do not use nearest-version symbols. Features requiring unavailable anchors remain disabled until an exact signed compatibility entry or bundled map exists.

For best experience, do not update Zalo.

Features

  • Clean up bottom navigation, inbox, chat, and Me-screen surfaces.
  • Add inbox category controls for chats, groups, official accounts, and strangers.
  • Conservatively filter reviewed promotional notifications.
  • Suppress selected analytics and advertising paths.
  • Keep an optional local notification history with bounded retention and export.
  • Record one-to-one call audio after the user enables the feature.
  • Fetch signed exact-artifact compatibility mappings with bundled offline fallback.

Installation

  1. Install the signed APK from this repository's Releases page.
  2. Enable Zalo Patch in LSPosed.
  3. Scope the module only to Zalo (com.zing.zalo).
  4. Open Zalo Patch, choose settings, and use the explicit Restart Zalo action to apply them.

Call recording is opt-in. Users are responsible for complying with consent and recording laws.

Privacy

  • Diagnostic reports upload only after explicit user review and action.
  • Notification history stays in local app storage until exported or cleared.
  • Call recordings are stored on the device.

Source And Support

Zalo Patch is unofficial and is not affiliated with or endorsed by Zalo or VNG.

Releases

0.4.199

Stable

9/10/2026, 5:28:52 PM

  • Fix stale call-recording sessions when Zalo reuses callbacks across calls, and prevent recording from restarting on a deleted native peer.
  • Clear pending recorder connection state when a call ends before recording starts.
  • Reduce repeated notification-rule normalization and temporary reflection allocations.
  • Use short numeric version names.

Requires Android 8.0 or newer and a framework supporting LibXposed API 102. Current mapped Zalo version: 26.08.02 (260802903).

Validation: JVM tests, release lint, static checks, and 60 preservation-aware device instrumentation tests passed. Incoming-call recording was observed saving M4A on the preceding build with the same recorder code. Consecutive incoming/outgoing calls, direct video calls, and voice-to-video transitions remain unverified; this release does not establish that all intermittent call cancellations are resolved.

Assets

1

0.4.204

Stable

9/14/2026, 11:13:58 AM

  • On unmapped Zalo versions, the Zinstant message and feed ad-binding anchors are now resolved on-device via semantic DEX fingerprints (DexKit 2.2.0), validated against live structural preflight, cached locally, and applied at the next Zalo restart. Exact bundled and signed catalog profiles keep precedence when valid.
  • Ambiguous or failed resolutions fail closed: the affected ad hiding stays disabled instead of borrowing a neighboring version's symbols. All other features keep the existing neighboring-profile fallback.
  • Scan retries are budgeted (3 failures per 24 h) and cache entries are bound to the installed Zalo code, query revision, resolver format, and module version.
  • Adds native DexKit libraries for arm64-v8a, armeabi-v7a, x86, and x86_64 (~1.4 MB).

Requirements: Android 8.0+, LSPosed with LibXposed API 102. Zalo 26.06.02-26.08.02 uses bundled exact profiles; other versions use the DexKit pilot path.

Verification: exact-profile path device-verified on the primary test device and a daily driver (settings preserved, 60 release-signed instrumentation tests, runtime self-check green, zero failed/stale rows); DexKit unknown-artifact path device-verified end to end on the primary test device (795 ms scan, unambiguous matches, warm-cache activation, live ad-bind collapse). Genuinely unmapped Zalo artifacts and LSPatch compatibility are not yet verified.

Known limits: the DexKit pilot covers the two Zinstant ad-bind anchors only; a first scan applies at the next Zalo restart; LSPatch is unsupported until separately verified.

Assets

1

8/24/2026, 8:30:29 AM

What's changed

  • Keep Zalo unlocked longer after it goes to the background. Zalo's own passcode lock allows at most
    30 seconds; the new Security setting offers 1, 2, 5, 10, 15, and 30 minutes, and 1 hour.
  • The setting is off by default, and only affects the app-wide passcode lock. Hidden chats, the
    encrypted backup PIN, and biometric unlock are untouched.

Requirements

  • Rooted Android device with LSPosed.
  • Zalo selected in the module scope.
  • Zalo 26.08.01 (versionCode 260801903).

Known limits

  • The longer grace period has not been confirmed on a test device yet. If the passcode still appears
    early, please report it.
  • Zalo's own passcode settings screen shows no selected option for a duration it does not offer.
    This is expected and does not affect the module setting.

Assets

1

8/21/2026, 11:57:15 AM

What's changed

  • Add optional frequent scheduled message backups with 1, 3, 6, or 12 hour intervals.
  • Preserve Zalo's native automatic-backup toggle, server, battery, network, retry, overlap, migration, restore, and separate media-upload guards.
  • Consolidate Restart Zalo into one action. Without root, it opens Zalo app info for manual force-stop and reopen.
  • Move Root access and Runtime environment details into Developer tools.

Assets

1

8/16/2026, 10:55:02 PM

Compatibility fix for Zalo installs whose base APK container differs from the one a symbol profile was mapped from. Google Play serves per-device bundle variants and re-stamps its signing block per download, so one Zalo release has several base APK hashes over identical code. Those installs were rejected outright and ran no features while the symbol schema still reported valid.

  • match on exact Zalo versionCode plus the Zalo signing certificate; container hash recorded as evidence
  • adding an on-demand Zalo feature split, or reinstalling Zalo, no longer disarms features
  • a Zalo version with no bundled profile records which anchor families resolve, without hooking anything
  • self-check detail and error text excluded from diagnostic reports

Bundled profiles cover Zalo 26.06.02, 26.07.01 and 26.08.01. Verified on one device.

APK SHA-256 c2ecdf315cc153e1c4f3c21b8cea5b3367f917f3cbca719ff3bd76f39a3fee45

Assets

1

8/16/2026, 7:46:02 AM

Initial LSPosed repository release of Zalo Patch.

  • Supports exact Zalo 26.08.01 (versionCode 260801903).
  • Adds Zalo UI cleanup, conservative promotional notification filtering, privacy controls, local notification history, and opt-in one-to-one call audio recording.
  • Uses signed exact-artifact compatibility mappings with bundled offline fallback.

Source and full verification notes: https://github.com/amarinne/zalo-patch/releases/tag/v0.4.151

APK SHA-256: bc41a8394e8bd4b33b0579033f1ce57ffc97c940267730eb5b96e66e3cc8fd70
Signing certificate SHA-256: 96a4240fa44a63a4a71738b2851064b97a2f500e07d42a26a190a783bbad65a9

Assets

1