
CVE-2026-20637-AppleSEPKeyStore-UAF
CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)

CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)



Offensive Software Exploitation Course

My proof-of-concept exploits for the Linux kernel

Shellcode Compiler

An experimental webkit-based kernel exploit (Arb. R/W) for the PS5 on <= 4.51FW

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0, 8.8.1

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)

Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit

This is an exploit for CVE-2020-0674 that runs on the x64 version of IE 8, 9, 10, and 11 on Windows 7.



Foxit PDF Reader Remote Code Execution Exploit

CVE-2025-38001: Linux HFSC Eltree Use-After-Free - Debian 12 PoC

Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers