
CVE-2025-54957
Proof-of-concept exploit for CVE-2025-54957, an out-of-bounds write in Dolby's DDPlus Unified Decoder, demonstrating a 0-click crash on Android via…

Proof-of-concept exploit for CVE-2025-54957, an out-of-bounds write in Dolby's DDPlus Unified Decoder, demonstrating a 0-click crash on Android via…

Exploit app for CVE-2022-20494, a high severity permanent denial-of-service vulnerability that leverages Android's DND (Do not disturb) feature

PoC code for CVE-2018-9539

Proof-of-concept exploit for CVE-2015-1474, demonstrating a rogue parcel crash in Android SurfaceFlinger via deserialization, enabling privilege…

GhostLock CVE-2026-43499 port for Galaxy Z Fold 8 (h8q)

Probes CVE-2026-0075 Android ContactsProvider side channel with a no-permission PoC, enabling root-cause analysis and patched-vs-vulnerable…

Local privilege escalation exploit for Pixel 3 (CVE-2020-0041) that disables SELinux and spawns a root shell via kernel memory corruption and offset…

Double-free vulnerability in DDGifSlurp in decoding.c in libpl_droidsonroids_gif can read more…

BlueStacks privilege escalation through VM backdooring

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

Arkhota, a web brute forcer for Android.

Pixnapping Attack: Compromising private keys and seed phrases through vulnerability CVE-2025-48561 represents a new critical threat to the Bitcoin…

Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a…

Use CVE-2026-43074 to disable SELinux on Android (Linux 6.6/6.12)

Proof-of-concept exploit for CVE-2026-14382, a high-severity ANGLE vulnerability in Chromium, with 32-bit and AArch64 PoCs achieving program counter…

Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

Proof-of-concept exploit for Android local privilege escalation (CVE-2014-7911) targeting Nexus5 with ROP chain and heap spraying to gain system uid.
