
Broadpwn
Broadpwn bug (CVE-2017-9417)

Broadpwn bug (CVE-2017-9417)

Jailbreak for A8 through A11, T2 devices, on iOS/iPadOS/tvOS 15.0, bridgeOS 5.0 and higher.

Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68

Trinity Exploit - Emulator Escape

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

MikroTik remote jailbreak for v6.x.x

AirPods liberated from Apple's ecosystem.

Patching and hooking the Linux kernel with only a stripped Linux kernel image.

Mediatek Flash and Repair Utility

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Exploit that extracts Qualcomm's KeyMaster keys using CVE-2015-6639 and CVE-2016-2431

CVE-2025-21479 proof-of-concept, I think

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

Glass - a fast and free IDA Pro alternative

Qualcomm TrustZone kernel privilege escalation

Cert exploit for MTK devices.There is a logic flaw in MTK cert verification process.Similar to CVE-2023-20696.

Low-level kernel modules and device tree source for the OnePlus 11 (sm8550), enabling hardware bring-up, driver analysis, and embedded system…

A proof-of-concept for CVE-2020-12753