You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Xposed:Hook LoadedApk嵌套类带参构造方法时出现NoSuchMethodError

Fixing java.lang.NoSuchMethodError: android.app.LoadedApk$ReceiverDispatcher()#exact When Hooking Constructors

Hey there, I’ve dealt with this exact Frida hook issue multiple times when working with Android framework classes—let’s break down why this is happening and how to fix it step by step:

Common Causes & Solutions

1. Mismatched Constructor Signature (Most Likely Culprit)

Android framework classes like LoadedApk$ReceiverDispatcher often have constructor parameters that change across API levels. For example, a constructor that takes 4 arguments in API 28 might add an extra parameter in API 33. If your hook code uses the wrong parameter types/order, Frida can’t find the exact method and throws this error.

Fix:

  • First, get the exact constructor signature from your target device’s framework:
    • Use a tool like Jadx to decompile /system/framework/framework.jar (or the relevant framework module for your device) and look up android.app.LoadedApk$ReceiverDispatcher and its Args inner class.
    • Alternatively, run this Frida script to enumerate all constructors for the classes:
      Java.perform(() => {
        // Enumerate ReceiverDispatcher constructors
        const ReceiverDispatcher = Java.use("android.app.LoadedApk$ReceiverDispatcher");
        console.log("\n=== ReceiverDispatcher Constructors ===");
        ReceiverDispatcher.class.getDeclaredConstructors().forEach(ctor => {
          console.log(ctor.toString());
        });
      
        // Enumerate Args constructors
        const Args = Java.use("android.app.LoadedApk$ReceiverDispatcher$Args");
        console.log("\n=== Args Constructors ===");
        Args.class.getDeclaredConstructors().forEach(ctor => {
          console.log(ctor.toString());
        });
      });
      
  • Update your findAndHookConstructor call to match the exact parameter list from the output. For example, if the constructor is LoadedApk$ReceiverDispatcher(LoadedApk, Context, IntentReceiver, boolean, String), your hook should look like:
    Java.perform(() => {
      const ReceiverDispatcher = Java.use("android.app.LoadedApk$ReceiverDispatcher");
      Java.findAndHookConstructor("android.app.LoadedApk$ReceiverDispatcher", {
        returnType: 'void',
        argumentTypes: ['android.app.LoadedApk', 'android.content.Context', 'android.content.IntentReceiver', 'boolean', 'java.lang.String']
      }, function(param) {
        console.log("ReceiverDispatcher constructor called:");
        console.log("LoadedApk:", param.args[0]);
        console.log("Context:", param.args[1]);
        // Access other parameters as needed
        param.thisObject.$init.apply(param.thisObject, param.args);
      });
    });
    

2. Incorrect Inner Class Reference or Access Permissions

Double-check that you’re referencing the inner classes correctly:

  • Static inner classes use the Outer$Inner syntax (e.g., android.app.LoadedApk$ReceiverDispatcher), which you’re probably doing right—but a typo here would cause Frida to look for a non-existent class.
  • Some constructors might be package-private or private, but Frida can still hook them as long as you reference the correct class. The error you’re getting points to a missing method, not a permission issue, but it’s worth verifying.

3. Hidden/Modified Constructors (Custom ROMs or OEM Changes)

On some devices, manufacturers modify framework classes or hide certain constructors. In this case, exact matching might fail.

Fix:

  • Use Frida’s overload matching or hook all constructors generically:
    // Hook all ReceiverDispatcher constructors
    Java.perform(() => {
      const ReceiverDispatcher = Java.use("android.app.LoadedApk$ReceiverDispatcher");
      ReceiverDispatcher.$init.implementation = function() {
        console.log("ReceiverDispatcher constructor invoked with arguments:", arguments);
        // Call the original constructor
        return this.$init.apply(this, arguments);
      };
    
      // Do the same for Args
      const Args = Java.use("android.app.LoadedApk$ReceiverDispatcher$Args");
      Args.$init.implementation = function() {
        console.log("Args constructor invoked with arguments:", arguments);
        return this.$init.apply(this, arguments);
      };
    });
    
  • If you need to target a specific overload, use overload() with the correct parameter types:
    ReceiverDispatcher.$init.overload('android.app.LoadedApk', 'android.content.Context').implementation = function(apk, ctx) {
      console.log("Targeted overload called");
      return this.$init(apk, ctx);
    };
    

4. Frida Version Compatibility

Outdated Frida versions might have issues hooking newer Android framework classes. Make sure you’re running the latest stable version of Frida and Frida-server, and that the server matches your device’s architecture (arm, arm64, x86, etc.).

Final Checklist

  1. Verify constructor signatures with enumeration scripts or decompilation.
  2. Fix any typos in class names or parameter lists.
  3. Fall back to generic or overload-based hooking if exact matching fails.
  4. Update Frida to the latest version.

内容的提问来源于stack exchange,提问作者Petitz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:32:29