
CVE-2019-2215
Android kernel exploit for CVE-2019-2215, a use-after-free in the Binder driver, enabling privilege escalation to root via memory corruption and cred…

Android kernel exploit for CVE-2019-2215, a use-after-free in the Binder driver, enabling privilege escalation to root via memory corruption and cred…

Intentionally vulnerable Android banking app for practicing mobile security testing, featuring root detection, anti-debugging, SSL pinning, and…

A tool that allows you to search for vulnerable android devices across the world and exploit them.

CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android

Intentionally vulnerable Android application.

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

AOSP Bluetooth stack repository modified for CVE-2021-0435, providing a patched or vulnerable version for analysis and testing of Bluetooth…

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

Intentionally vulnerable hybrid Android app for security professionals to test tools and techniques, and for developers to learn common hybrid mobile…

Local privilege escalation proof-of-concept for CVE-2023-20938, a use-after-free in Android binder, achieving root and disabling SELinux on…

Android Bluetooth stack (Fluoride) with a specific patch for CVE-2022-20229, providing a vulnerable version for security research and exploit…

PoC for CVE-2016-5345

AOSP Bluetooth stack with a patch for CVE-2021-0589, providing a vulnerable version for security research and exploit development.

Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass

Differential detection harness for CVE-2026-76036, a Dawn WebGPU heap buffer overflow in Chrome on Android. Probes vulnerable depth/stencil texture…

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.