
aotopsy
Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)

PoC and analysis of a zero-click DoS in Android's DNG SDK, with crafted DNG samples, an NDK crash harness, and UBSan/IntSan reproduction of the…

Build and query a graph database representation of source code

Minimal CVE-2025-69421 reproducer demonstrating a NULL pointer dereference in OpenSSL PKCS#12 processing via a malformed PFX file with absent…

Reproducible CVE-2026-36834 proof-of-concept demonstrating an out-of-bounds array read in LibRaw's Panasonic RW2 decoder, with mutation script and…

SolarWinds Serv-U CVE-2026-28318: unauthenticated Content-Encoding: deflate crash. Root-cause analysis (invalid free of an interior pointer -> heap…

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

Proof-of-concept exploit for CVE-2026-3909, a Chromium Skia out-of-bounds vulnerability, with patches and crash analysis for reliable triggering in…

Proof-of-concept exploit for CVE-2025-50420 demonstrating infinite recursion in Poppler's pdfseparate via crafted /Annots dictionaries, causing…


A MediaTek modem input validation issue can cause a system crash (remote DoS) when a UE connects to a rogue base station controlled by an attacker…

Analysis and PoC for CVE-2025-14174 - ANGLE Metal OOB write (iOS Safari, macOS Chrome)

Proof-of-concept for CVE-2024-44083: IDA Pro ≤8.4 crash via excessive jump chains causing stack overflow. Includes technical analysis, reproduction…

Proof-of-concept for CVE-2025-62454 that triggers a Windows kernel crash (BSOD) in cldflt.sys via a crafted FSCTL request, causing a page fault in…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Proof-of-concept exploit for CVE-2025-11579, a denial-of-service vulnerability in rardecode that triggers an out-of-memory crash via a crafted RAR…

Proof-of-concept exploit for CVE-2025-46819, a Redis Lua long-string delimiter out-of-bounds read, demonstrating a crash via malformed input.