
oxasploits
A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

Work in Progress for POC

Proof-of-concept exploit for iOS Bluetooth stack vulnerabilities CVE-2018-4327 and CVE-2018-4330, enabling ARM PC register control on iPhone 6S via…

Proof-of-concept for CVE-2025-63895: Bluetooth Classic LMP buffer overflow exploitation in JXL 9-inch Android car infotainment systems, enabling…

repo for CVE-2025-52413

This report is for CVE-2025-56019 reserved for Easytouch+product for BLE authentication vulnerability assigned to Discoverer Yashodhan Vivek Mandke.…

Exploit for CVE-2021-0507, a remote code execution vulnerability in Android's Bluetooth stack (system/bt). Provides proof-of-concept for the flaw.

Android Bluetooth stack (Fluoride) with a proof-of-concept for CVE-2022-20140, demonstrating a Bluetooth vulnerability and providing build…

Android Bluetooth stack (AOSP 10 r33) with fix for CVE-2021-0435, addressing remote code execution in Bluetooth pairing.

Android Bluetooth stack (Fluoride) source code for AOSP 10 r33, specifically related to CVE-2021-0431 Bluetooth vulnerability research and…

Bluetooth Classic HID injection exploit for CVE-2023-45866, enabling unauthenticated keystroke injection against vulnerable BlueZ-based Linux systems.

BLE-based HTTP proxy system routing browser traffic through an iOS device. Supports HTTP/HTTPS, data compression, and mock mode for testing without…

Implementation of Key Negotiation Of Bluetooth (KNOB) attacks targeting Bluetooth BR/EDR and BLE, exploiting CVE-2019-9506 for security research and…

Detailed analysis and proof-of-concept for CVE-2023-46870, a local privilege escalation in Nordic Semiconductor nRF Sniffer for Bluetooth LE due to…

Bluetooth keyboard injection exploit for CVE-2023-45866 targeting Android, iOS, macOS, and Linux devices. Simulates HID device to execute automated…

A writeup and theoretical Proof-of-Concept for CVE-2019-19194

Proof-of-concept exploit for CVE-2024-34463 targeting insufficient Bluetooth security in BPL Smart Weighing Scale PWS-01-BT. Includes BLE scanner and…

Proof-of-concept exploit for CVE-2024-21306 targeting Bluetooth stacks. Demonstrates vulnerability exploitation via Bluetooth interface manipulation…