
IonStack-S22U
CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)

CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)

CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)

Elevates a low-privilege Windows process to SYSTEM via a gdb-assisted ROP token-swap chain, demonstrating CVE-2026-62737 in a lab-only QEMU…

Stack buffer overflow PoC for a hardware wallet USB descriptor parser (CVE-2026-22013), showing return-address overwrite and code execution via…

Stack buffer overflow PoC in an embedded TLS certificate parser using a crafted X.509 SAN extension for remote code execution on IoT and industrial…

Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load

Exploit for CVE-2021-0507, a remote code execution vulnerability in Android's Bluetooth stack (system/bt). Provides proof-of-concept for the flaw.

Exploit chain targeting iOS devices via WebKit and kernel vulnerabilities, delivering privilege escalation and post-exploitation payload for…

open-source jailbreaking tool for many iOS devices

Proof-of-concept exploit for CVE-2023-28588 in Android system Bluetooth, enabling remote code execution via crafted packets.

CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (COMPLETED)

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets

Proof-of-concept exploit for CVE-2022-31705, a VMware EHCI out-of-bounds write vulnerability. Demonstrates OOB memory corruption via crafted USB…

Bluetooth RFCOMM memory disclosure exploit framework for CVE-2025-13834, enabling unauthenticated OOB read of kernel/heap memory from 2.8 billion…

Technical disclosure of four unauthenticated RCE vulnerabilities (CVE-2020-25782/3/4/5) in Accfly wireless security cameras, including stack/heap…

Windows utility that uses the vulnerable WiseDelfile64.sys driver affected by CVE-2025-66680 to enable kernel-assisted file deletion.

Proof-of-concept exploit for CVE-2018-4330 targeting iOS Bluetooth daemon, allowing ARM PC register control on iPhone 6S (iOS 11.3.1–11.4).