
CVE-2026-43499-IQOO-Neo10-Analysis
Technical analysis repository for CVE-2026-43499, covering root-cause investigation, impact assessment, and mitigation guidance for the IQOO Neo10…

Technical analysis repository for CVE-2026-43499, covering root-cause investigation, impact assessment, and mitigation guidance for the IQOO Neo10…

GhostLock (CVE-2026-43499) for the Galaxy S26

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled

Builds a root exploit for vivo/iQOO devices targeting CVE-2026-43499, leveraging kernel techniques like KASLR bypass and CFI manipulation to achieve…

Weaponized proof-of-concept for CVE-2026-0073, an Android adbd authentication bypass enabling zero-click remote root access via Wireless ADB, with…

Proof-of-concept exploit for CVE-2026-0073, an Android ADB authentication bypass allowing network attackers to connect to devices with ADB over TCP…

Android Bluetooth stack (Fluoride) with a specific patch for CVE-2021-0474, providing source code for building and testing the Bluetooth component on…

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

PoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta

Writeup and exploit for installed app to system privilege escalation on Android 12 Beta through CVE-2021-0928, a `writeToParcel`/`createFromParcel`…

Full-chain exploit for Android Chromium combining CVE-2026-11057 info leak and CVE-2026-5281 use-after-free to achieve vtable hijack and arbitrary…

AOSP Bluetooth stack repository modified for CVE-2021-0435, providing a patched or vulnerable version for analysis and testing of Bluetooth…

Android framework patch for CVE-2021-0595, addressing a security vulnerability in the Android operating system.

Proof-of-concept exploit for CVE-2025-10184, demonstrating a permission bypass in the OxygenOS Telephony provider on Android devices.

Android Settings package with a fix for CVE-2021-39706, addressing a security vulnerability in AOSP 10.

Android Settings app source code for AOSP 10 r33, patched for CVE-2021-0336, for vulnerability analysis and security research.

Android media framework vulnerability fix for CVE-2021-0509, addressing a use-after-free in audio flinger to prevent local privilege escalation.