
rizin
UNIX-like reverse engineering framework and command-line toolset.

UNIX-like reverse engineering framework and command-line toolset.

KSU installer for supported firmware with CVE-2026-43499

GhostLock CVE-2026-43499 port for Galaxy Z Fold 8 (h8q)

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Academic Research Edition - T1: User-mode evasion (obfuscation + syscall gateway), T2: BYOVD kernel bridge, T3: DMA hardware (future work).

An exploit to CVE-2020-0423, which is a Binder deffered work UAF.

MOC3ingbird Exploit for Live2D (CVE-2023-27566)

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

Provides a ctypes wrapper for the splice syscall to enable exploitation of CVE-2026-31431 on Python versions below 3.10, tested on Python 3.7.3.

Local privilege escalation exploit for ASUS AsIO3.sys driver (CVE-2025-3464). Chains a TOCTOU authentication bypass with a kernel decrement primitive…

Researching CVE published originally by longterm.io

Productization efforts of CVE-2020-11179 Adreno-Qualcomm-GPU bug, original poc by Ben Hawkes of P0

poc for CVE-2022-32981 under work

CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)

Proof-of-concept exploit for CVE-2024-32002, demonstrating RCE via git clone with malicious submodules and symlinks on case-insensitive filesystems.

fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command