Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
skeleton — Zero-click remote code execution exploit for CVE-2021-0326 targeting Android devices, including the Peloton Bike, with a proof-of-concept requiring ASLR disabled. | Kitploit
Tools/GitHubGitHub/aemmitt-ns/skeleton
Android SecurityExploit FrameworksVulnerability AnalysisExploitationMobile SecurityBinary Exploitation
GitHubaemmitt-ns/skeleton

skeleton

Zero-click remote code execution exploit for CVE-2021-0326 targeting Android devices, including the Peloton Bike, with a proof-of-concept requiring ASLR disabled.

View Repository
2184 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Skeleton (but pronounced like Peloton)

A Zero-Click RCE exploit for CVE-2021-0326 on the Peloton Bike

And also every other unpatched Android Device

PoC requires ASLR to be disabled.

Associated blog post: https://www.nowsecure.com/blog/2022/02/09/a-zero-click-rce-exploit-for-the-peloton-bike-and-also-every-other-unpatched-android-device/

diagram of exploit

Download Tool