HushGram v0.0.5 has 48 patches for Instagram 449.0.0.52.84 (arm64-v8a, version code 385511871), two more than v0.0.4. The new ones are Hide the notes row and View DM photos and videos anonymously, and both start off until you turn them on. This release needs Morphe Manager 1.33.0 or newer. It still runs on Android 9 and newer. Here's everything that changed.
- HushGram 0.0.5 adds two patches, for 48 in all, and still targets Instagram 449.0.0.52.84 (build 385511871, arm64-v8a) on Android 9 and newer.
- HushGram now builds on Morphe patcher 1.15.0, so it needs Morphe Manager 1.33.0 or newer. Manager 1.32.0 asks for an update before it loads the bundle.
- New patch,
Hide the notes row, in Manager's simple mode with its switch off. Turn it on under Messages in HushGram settings and the row of notes at the top of your messages goes, along with the Map bubble that sits in it. Your chats, search and message requests stay where they are. Asked for in #17. - HushGram's settings come in Korean now, translated by @BlackGold8282 in #36.
- Following-list labels now wait for Instagram's row friendship status instead of trusting a stale profile fallback, so accounts won't show "Doesn't follow you" until their profile refreshes.
- Pure black dark mode now leaves bottom navigation icon colors alone when they share Instagram's dark Prism value, so the buttons stay visible on black backgrounds.
- The source catalog makes six initially neutral controls available in Manager's simple mode. Copy comment, Save comment photo, Hide highlights, Stop swipe to create and Stop Reels scrolling still start off. Story ring size starts at Instagram's own size. Saved choices stay intact. Stop swipe to create checks its switch before making added native reads, so off, Pause and startup before settings are ready retain the original path.
- Keep Reels auto scroll on remembers a completed future timer immediately, so it stays on even if the timer expires before another reel checks it. Cancelled choices, expired timestamps and paused runs keep their usual behavior. Its startup summary appears once at each readiness state, including when checks run together.
- Stop Story auto-advance checks the actual story loop flag before adding its guard. Hide highlights refuses branches into the row's type read or add. Native bundle checks pin the story guard's exact loop call and preserve the original handler's call.
- Story retry patching checks that the native queue count and account reads leave pending batches alone. It refuses subclasses of the final story store, including inherited builder references hidden in encoded handles. A retry bridge with no executable DEX body also stops patching.
- About and local diagnostic reports show the production build identity, so different source builds of the same version can be identified.
- Turning all three suggestion switches under Feed off restores Instagram's own empty feed behavior in the same run. Removing a suggestion earlier no longer keeps the filtered feed's end state active.
- Settings ignore stale accessibility clicks after a containing section is removed or the page closes. Disabling a container disables its controls' accessibility actions. Search refuses edits and Clear after its page closes. A focus-clear action releases the search view hold even when accessibility is off. Android 9 and 17 regressions cover current screen changes and disabled ancestors.
- Override recovery keeps the selected saved copy through interrupted saves and moves. Cleanup failures stay visible even when changes have already applied. Restore removes temporary replacement copies after recovery finishes, and Discard can remove a damaged backup or recovery record. It also recovers when a lone completion record can't be read. The terminal recovery journal is moved to a completion record, keeping imports blocked while its final storage flush fails even if no replacement file can be written.
- View stories anonymously keeps saved batches held if reading the switch, choosing marked stories or creating their batch fails, including an allocation failure. Every retry checks the batch again before Instagram takes ownership or creates a request. It no longer removes a held batch or falls back to sending its original contents. Turning the switch off or pausing keeps Instagram's usual behavior.
- Import, Restore and Discard recheck their permission after reading native state. Turning Allow importing overrides off or pausing while an import waits now stops it before any typed write or recovery-file change. Permission is checked again after file staging and before the first native change, preserving the earlier saved copy if permission changed.
- Added the opt-in patch
View DM photos and videos anonymously, with a separate switch that starts off. It holds back the visual photo/video opened receipt and completes Instagram's queued visual task locally. Ordinary message and voice receipts keep their existing path. Hide Meta AInow covers its optional message composer buttons through Instagram's existing visibility and layout path, and omits the optional inbox row through its native empty-row branch. Native fixture tests preserve ordinary controls and thread lists.- Same-key provider trust now checks the caller's actual current signing key after Instagram's native decision. Only named family apps in the same Android user can qualify. Other provider policies and the original deep-link certificate answers stay intact.
- Disable analytics also skips contacts and location setup delivered through the direct screen presenter. It checks the same two setup screen identifiers and keeps the native path for ordinary screens and absent screen data.
- Open MetaConfig overrides passed the signed-out Samsung check. Its row kept the complete unavailable reason and settings stayed open.
- The reporter confirmed that Clean up Reels now hides the friends' activity and closed #7.
- The reporter confirmed Discover people and suggested users in Reels in #15.
Tooling
- smali now matches the commit patcher 1.15.0 asks for. The old pin was one commit behind it but sorted higher, so Gradle had been compiling and testing against the older dexlib2. The fixture gates move to desktop CLI 1.18.0.
- Wrapper checks find Git Bash when Git hooks resolve an internal Git executable. The authentic Windows and POSIX launchers and every refusal-before-execution check remain required.
- Local builds default to two workers at low priority, with parallel project builds off. Patch tests use a 4 GB heap instead of 8 GB, and test JVMs limit their internal processor count to two. Build caching stays on.
- Bug reports offer direct messages, profiles and Explore, with a link to local diagnostics and build details. The settings guide separates confirmed suggestion controls from optional profile rows, and the source guide matches the latest recorded census. Manager's story patch description matches the guide.
- Refuse ignored compiler and packaging inputs in production source sets before building or certifying a current dependency audit. Git ignore rules can no longer hide shipped code from its build identity. Staged development inputs still use their current working bytes, and release receipts still require clean sources. Debug, test and generated files remain excluded.
- Local patching checks each selected bundle's exact targets and dependencies before merging or changing an APK. Reports identify the bundle by its hash and attribute initializer failures to their dependency owner. Conflicting selected extension definitions are refused, while compatible addons keep their native initialization. Bug reports now ask which sources and bundle versions were selected.
- New release receipts map the canonical source, catalog and toolchain identity to final bundle and extension hashes. The identity includes Android release source sets, so a change there produces a different identity even when the version stays the same. Debug and test inputs stay excluded. Historical receipts keep their original reading rules.
- Every required Android boundary result now names its actual Android SDK, including the highest SDK in a test class. The gate refuses Android 16 results substituted for Android 17 and results with their platform label removed. All provider caller cases remain required. Self-tests also check missing, filtered, skipped, failed and duplicate results through the real Gradle task, then restore the original report.
- Both Gradle launchers verify the reviewed wrapper JAR and distribution checksum before wrapper code runs. Altered, missing or unreviewed wrappers stop direct builds and scripted builds with a useful error. The push gate exercises both launchers with a runnable replacement JAR.
- Bind current dependency audits to source, catalog, toolchain, SBOM and bundle bytes, preserve resolved dependency edges, and update affected settings and UTP tools to compatible Commons Lang and HttpClient fixes.
- The shipped SBOM now records reviewed Apache 2.0 licenses for its exact Gson, Kotlin stdlib and JetBrains annotations artifacts. Publisher POM and binary hashes bind each record. NOTICE names the carried libraries. Current dependency audits and new release receipts refuse omitted libraries, missing evidence or substituted hashes while historical receipts stay readable.
- Added local Crowdin setup with resumable draft imports and a review package for German, Spanish, Indonesian, Brazilian Portuguese, Turkish and Korean. Setup requires the owner's token, preserves existing reviewer work and never approves translations. Translation tests now run before a related push.
- Gave the native patch test suite enough heap for the expanded fixture proofs. The default test-worker heap ran out while reading whole APK methods.
- Story retry proofs now reject callers that bypass the protected queue, including additional interfaces and stored method handles. They also reject changed ownership predicates and mismatched disk cleanup arguments. Native helper bodies identify the saved key and cleanup operation. The DEX contract checks the story store guard and the null branch before ownership changes.
Install or update
- Update Morphe Manager to 1.33.0 or newer first. Older versions ask for an update before they load this bundle.
- Add the source with the link in the README, or update it if you already have it.
- Patch the arm64-v8a build of Instagram 449.0.0.52.84, version code 385511871. The .mpp is a patch bundle, not an Instagram APK.
- Keep the manager's signing key for updates, so a new build installs over the old one and you stay signed in.
- Read Before you sign in in the README first. A spare account keeps your main one out of it.
Validation
1491 runtime tests and all 686 patch tests passed locally. All 48 patches applied to Instagram 449.0.0.52.84 without forcing, and the resource and injected-code checks passed. The receipt and SHA256SUMS.txt beside the bundle list every file's hash.