
SmmExploit
The report and the exploit of CVE-2021-26943, the kernel-to-SMM local privilege escalation vulnerability in ASUS UX360CA BIOS version 303.

The report and the exploit of CVE-2021-26943, the kernel-to-SMM local privilege escalation vulnerability in ASUS UX360CA BIOS version 303.

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…

Curated proof-of-concept exploits for real-world CVEs affecting iOS, macOS, Chrome Renderer, and Steam clients, with version-specific targets and…

Proof-of-concept exploit for CVE-2023-41993, a WebKit JIT type confusion in Safari. Provides addrof/fakeobj primitives via heap manipulation and…

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

Automated ROP chain generator for x86-64 binaries using symbolic execution. Supports register/memory writes, function calls, syscalls, badchar…

Exploit for CVE-2017-1000367: local privilege escalation via sudo's SELinux role bypass on selinux-enabled systems. Requires sudo permissions and…

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

Information and PoC about the ENLBufferPwn vulnerability

Proof-of-concept exploit for CVE-2021-28663, a design flaw in the Mali GPU Android kernel driver enabling arbitrary read via memory alias and…

A method for CVE-2025-31710 and to connect to cmd_skt to obtain a root shell on unisoc unpatched models

Go package that aids in binary analysis and exploitation

Full exploit of CVE-2016-6754(BadKernel) and slide of SyScan360 2016

POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY

A webkit-based kernel exploit and jailbreak for PS5

Exploit for CVE-2018-8120, a Windows local privilege escalation vulnerability, providing a working proof-of-concept for security testing and research.