
oxasploits
A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…

poc for CVE-2023-23388 (LPE in Windows 10/11 bthserv service)

cabin partial analysis

Vulnerability proof of concept reworked from https://github.com/utmost3/cve/issues/2 I take no credit for discovering the vulnerability. This is for…

Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC) BlueBorne - Proof of Concept - Unarmed/Unweaponized - DoS (Crash) only

system_bt_CVE-2023-28588

Android Bluetooth stack (Fluoride) with a proof-of-concept for CVE-2022-20140, demonstrating a Bluetooth vulnerability and providing build…

Linux Bluetooth - Run arbitrary management commands as an unprivileged user

POC for CVE-2018-4327

PoC for CVE-2019-10207

CVE-2020-12351

CVE-2025-13834 Technical Summary Vulnerability Type: Memory Disclosure / Out-of-Bounds (OOB) Read (CWE-125). CVSS Score: 7.5–8.1 (High/Critical). …

repo for CVE-2025-52413

Exploit for CVE-2021-0507, a remote code execution vulnerability in Android's Bluetooth stack (system/bt). Provides proof-of-concept for the flaw.

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

CVE-2018-4330 POC for iOS

Proof-of-concept exploit for iOS Bluetooth stack vulnerabilities CVE-2018-4327 and CVE-2018-4330, enabling ARM PC register control on iPhone 6S via…