
ctl_ctloutput-leak
CVE-2017-13868: Information leak of uninitialized kernel heap data in XNU.

CVE-2017-13868: Information leak of uninitialized kernel heap data in XNU.

Kernel Information Disclosure

Exploit analysis for CVE-2014-4378: information disclosure in Apple CoreGraphics via crafted PDF, enabling memory layout leak and bypass of ASLR,…

Proof-of-concept exploit for CVE-2021-31955, a Windows kernel information disclosure vulnerability. Demonstrates exploitation on 64-bit systems to…

Exploit for CVE-2023-21688 combining a side-channel information leak with a use-after-free (UAF) chain for kernel privilege escalation.

Exploit for CVE-2019-6207: kernel heap information leak in getdirentriesattr on macOS <=10.14.4 and iOS <12.2, triggerable from sandbox.

Proof-of-concept exploit for Linux kernel FUSE information leak (CVE-2024-44947), demonstrating beyond-EOF memory disclosure via mmap and including…

Technical analysis of CVE-2020-1206 (SMBleed) kernel information disclosure vulnerability in Windows SMBv3, including unauthenticated memory leak…

CVE-2018-4185: iOS 11.2-11.2.6 kernel pointer disclosure introduced by Apple's Meltdown mitigation.

Heap overflow exploit for CVE-2021-22555 achieving local privilege escalation to root on Ubuntu 20.04 with kernel 5.8.0-48.

open-source jailbreaking tool for many iOS devices

My proof-of-concept exploits for the Linux kernel

Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel,…

Search for Unix binaries that can be exploited to bypass system security restrictions.

Windows KASLR bypass using prefetch side-channel

CVE-2019-0708 (BlueKeep)

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

Spectre exploit