
Android netd vulnerability analysis and exploitation research for CVE-2023-40084, focusing on the platform's network daemon.

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.




Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…



JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Exploit and writeup for installed app to root privilege escalation through CVE-2024-48336 (Magisk Bug #8279), Privileges Escalation / Arbitrary Code…

CVE-2017-13286 Poc(can not use)

Android MediaProvider vulnerability analysis and patch for CVE-2023-40127, focusing on security assessment and remediation.

Android platform framework repository containing a patch or analysis for CVE-2023-21288, a vulnerability in the Android framework.

Android platform framework patch for CVE-2023-21281, addressing a security vulnerability in the Android framework.