
ztewaste
Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor…

Poc of CVE-2020-0113 & CVE-2020-0108

Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device…

CVE-2026-0013 Android EoP PoC - Compiled artifacts for security research (Derivative of inforcqb/cve-2026-0013-exploit)

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it…

Location tracking app without location permissions! Makes use of CVE-2018-15835 which makes use of Android OS information leakage.

CVE-2023-27703 An Android version of pikpak version V1.29.2 element debugging interface leakage vulnerability

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

A poc for a vulnerability in ZTE File Manager (zte.com.cn.filer) which allows to read arbitrary files from other apps as the privileges of this file…

Frida script that bypasses VMProtect runtime protections on mobile platforms, enabling dynamic instrumentation and analysis of protected binaries.

A set of scripts that ease working with frida

Detailed discussion of Zygote vulnerability CVE-2024-31317

Proof of concept for CVE-2026-36027 and CVE-2026-36028

Proof of concept of CVE-2017-0807

PoC and analysis of a zero-click DoS in Android's DNG SDK, with crafted DNG samples, an NDK crash harness, and UBSan/IntSan reproduction of the…

Exploit script for CVE-2017-0785 that crashes the Bluetooth module on Android 4.0+ devices by sending crafted SDP search requests, causing…