
PCAPdroid
No-root network monitor, firewall and PCAP dumper for Android

No-root network monitor, firewall and PCAP dumper for Android

Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

Allows you to emulate an Android native library, and an experimental iOS emulation

Full-chain exploit for Android Chromium combining CVE-2026-11057 info leak and CVE-2026-5281 use-after-free to achieve vtable hijack and arbitrary…

GhostLock CVE-2026-43499 port for Galaxy Z Fold 8 (h8q)

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Android client for Prey: reliable device tracking and security tool

Plugin for JADX to integrate MCP server

Proof-of-concept for CVE-2026-22010 Android intent redirection: demonstrates an exported activity forwarding intents to attacker-controlled internal…

GhostLock (CVE-2026-43499) kernel exploit for Poco M6 Pro (emerald) with locked bootloader

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Android Reverse-Engineering Workbench for VS Code

[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)

Proof of concept for CVE-2026-36027 and CVE-2026-36028

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…