
SpringPeace
(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499
This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

Step-by-step guide to building custom Kali NetHunter kernels for Android: source retrieval, toolchain selection, cross-compilation, and flashing.

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices


Analysis of public exploits or my 1day exploits

Analysis of public exploits or my 1day exploits

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

Mobile Application Vulnerability Detection

Improper Hostname Verification in EagleEyes Lite Android Application

A fully public exploit of the CVE-2020-0022 BlueFrag Android RCE Vulnerability (tested on Pixel 3 XL)

CVE-2026-43499 (IonStack/GhostLock) pure-C re-root POC for Samsung SM-T878U / gts7l (T878USQS8DXE1)

Magisk root guide for ZTE Blade X1001 (Android 15, Unisoc UMS9230) using CVE-2022-38694 exploit. Contributions and screenshots welcome.

CVE-2026-43499 exploit with OnePlus Ace3 support

Advanced per-app device / CPU / GPU spoofer for rooted Android — device profiles, per-app CPU models, prop & Android-ID spoofing, all driven by a…

Lab Exploit (CVE-2021-521): App uses Java reflection to access Android system components, retrieving a list of all installed apps. Reflection…

USB device fuzzing on Android Phone