
CTFs
CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done

CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done

KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration,…

Ghidra is a software reverse engineering (SRE) framework

UNIX-like reverse engineering framework and command-line toolset

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

Android 14 kernel exploit for Pixel7/8 Pro

Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215


CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

Kernel exploit research achieving temporary root on Amazon Fire 7 (Fire OS 7.3.3.1) via the Mali kbase JIT use-after-free CVE-2022-38181, with a…

Complete RMGP (CVE-2026-43499) workspace + experiment-state handoff for SM-A376B/A376BXXU1AZB7

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

CVE-2025-48593

Technical analysis of a critical zero-click remote code execution vulnerability (CVE-2025-48593) affecting Android 13-16, detailing root cause,…

Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

Unlock Bootloader for Itel S23 (S665L) / Unisoc T606 using CVE-2022-38694