
Awesome-MoAI-Security
Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

Advanced per-app device / CPU / GPU spoofer for rooted Android — device profiles, per-app CPU models, prop & Android-ID spoofing, all driven by a…

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

CVE-2026-43499 (IonStack/GhostLock) pure-C re-root POC for Samsung SM-T878U / gts7l (T878USQS8DXE1)

CVE-2026-43499 exploit with OnePlus Ace3 support

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

Step-by-step guide to building custom Kali NetHunter kernels for Android: source retrieval, toolchain selection, cross-compilation, and flashing.

Magisk root guide for ZTE Blade X1001 (Android 15, Unisoc UMS9230) using CVE-2022-38694 exploit. Contributions and screenshots welcome.

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.


A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Android remote administration tool

Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.