
wasm2c-tableflip
wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM

My experiments in weaponizing Nim (https://nim-lang.org/)

Open-source AI reverse-engineering agent using Ghidra and LLMs to reconstruct and validate C/C++ functions from binaries.

Dirty Pipe root exploit for Android (Pixel 6)

A plugin to introduce interactive symbols into your debugger from your decompiler

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)

PoC for CVE-2019-5736

binary patching from Python

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

Android 14 kernel exploit for Pixel7/8 Pro

Proof of concept for CVE-2015-7547

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House

Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple's XNU source.

Automated ROP chain builder that extracts and analyzes gadgets from binaries using semantic queries, supporting X86/X64 architectures with a Python…

CVE-2023-32233: Linux内核中的安全漏洞