
MobileApp-Pentest-Cheatsheet
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…


Simple POC for exploiting WhatsApp double-free bug in DDGifSlurp in decoding.c in libpl_droidsonroids_gif

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

Cleartext Transmission of Sensitive Information in EagleEyes Lite Android Application

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass

Double-free vulnerability in DDGifSlurp in decoding.c in libpl_droidsonroids_gif can read more…

Blueborne CVE-2017-0785 Android information leak vulnerability

Android APK Based On Public Information Using DirtyCOW CVE-2016-5195 Exploit

CVE-2017-0785: BlueBorne PoC

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Location tracking app without location permissions! Makes use of CVE-2018-15835 which makes use of Android OS information leakage.


A tool that enumerates Android devices for information useful in understanding its internals and for exploit development. It supports android 4.2 to…

Tool for leaking and bypassing Android malware detection system

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

Malware detection using learning and information retrieval for Android