
CVE-2016-5195
CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android

CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android

GhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader


Analysis of public exploits or my 1day exploits

Hands-on workshop for learning Android kernel vulnerability analysis and exploitation, with Docker-based build environment and practical exercises.

Dirty Pipe root exploit for Android (Pixel 6)

Android 14 kernel exploit for Pixel7/8 Pro

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

Linux kernel privilege-escalation exploit for CVE-2026-46242, a race-condition use-after-free in epoll, with 99% reliable root on desktops, servers,…

CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k

Exploit that extracts Qualcomm's KeyMaster keys using CVE-2015-6639 and CVE-2016-2431

Python exploit for CVE-2015-1538-1 targeting Stagefright's 'stsc' MP4 atom integer overflow to achieve remote code execution and a reverse shell on…

Metaphor - Stagefright with ASLR bypass

Exploit for CVE-2022-20452, privilege escalation on Android from installed app to system app (or another app) via LazyValue using Parcel after…

Collections of my POCs for android vendor CVEs

Exploits for Android Binder bug CVE-2020-0041

Bad Spin: Android Binder Privilege Escalation Exploit (CVE-2022-20421)

Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.