
DVHMA
Damn Vulnerable Hybrid Mobile App (DVHMA) is an hybrid mobile app (for Android) that intentionally contains vulnerabilities.

Damn Vulnerable Hybrid Mobile App (DVHMA) is an hybrid mobile app (for Android) that intentionally contains vulnerabilities.

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

Android contact manager that stores contacts in an isolated database, preventing other apps from accessing them. Provides call log and caller ID…

Frida-based runtime API monitor for Android apps that logs invoked APIs, parameters, return values, and call origins across predefined or custom…

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

A tool that enumerates Android devices for information useful in understanding its internals and for exploit development. It supports android 4.2 to…

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included

Exploit app for CVE-2022-20494, a high severity permanent denial-of-service vulnerability that leverages Android's DND (Do not disturb) feature

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Android kernel exploit for CVE-2026-43499 (Futex-PI use-after-free) that gains temporary root on Xiaomi XIG04 to enable ADB. Includes automated…

Android Debug Bridge (adb) was vulnerable to directory traversal attacks that could have been mounted by rogue/compromised adb daemons during an adb…

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

A tool that automates the mundane tasks of pentesting Android apps. It uses APKTool and Dex2Jar.