
StaCoAn
StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

Dynamic analysis sandbox for Android apps that monitors network traffic, file operations, cryptographic API usage, permission circumvention, and…

Static analysis tool for Android/iOS apps focusing on security issues outside the source code

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Arbitrary file read in BlueStacks

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

Static analysis tool for Android APKs that inspects Dalvik bytecode, decodes XML resources, and detects potential issues. Supports binary…

Penetration testing and auditing toolkit for Android apps.

DoS against Belkin smart plugs via crafted firmware injection

Scanning APK file for URIs, endpoints & secrets.

ES File Explorer Open Port Vulnerability - CVE-2019-6447

Exploit for CVE-2016-2434, a buffer overflow in Android mediaserver enabling arbitrary code execution via crafted media file.

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

Exploiting Android Vulnerability in ES File Explorer

Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android

Python exploit for CVE-2019-6447 enabling arbitrary file read on ES File Explorer 4.1.9.7.4 for Android. Demonstrates mobile vulnerability…

ES File Explorer v4.1.9.7.4 Open port vulnerability exploit. CVE-2019-6447