
DVHMA
Intentionally vulnerable hybrid Android app for security professionals to test tools and techniques, and for developers to learn common hybrid mobile…

Intentionally vulnerable hybrid Android app for security professionals to test tools and techniques, and for developers to learn common hybrid mobile…

Significant security enchancements of recent major Android versions.

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

PoC Frida script to view Android libbinder traffic

A method for CVE-2025-31710 and to connect to cmd_skt to obtain a root shell on unisoc unpatched models

Exploit and writeup for installed app to root privilege escalation through CVE-2024-48336 (Magisk Bug #8279), Privileges Escalation / Arbitrary Code…

Writeup and exploit for installed app to system privilege escalation on Android 12 Beta through CVE-2021-0928, a `writeToParcel`/`createFromParcel`…

Fuzzy comparison tool for deobfuscating Android APKs by identifying renamed functions across versions, generating mapping files and interactive HTML…

PulseAPK Core: Cross-Platform tool for working with APK files: Decompilation, Analysis, Building

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

Proof-of-concept exploit for CVE-2026-0073, an Android ADB authentication bypass allowing network attackers to connect to devices with ADB over TCP…

A Frida UI tool window inside PyCharm / JetBrains IDEs.

Android deeplink misconfiguration detector and exploitation tool

Android penetration testing tool for Kali linux

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…