
BlueToolkit
Modular Bluetooth Classic (BR/EDR) vulnerability testing framework with reconnaissance, exploit modules for 43 public attacks/CVEs, and structured…

Modular Bluetooth Classic (BR/EDR) vulnerability testing framework with reconnaissance, exploit modules for 43 public attacks/CVEs, and structured…

BLE exploit framework for Unitree robots: command injection via hardcoded AES keys enables remote takeover, payload injection, and wormable…

Metasploit module exploiting InfoBlox Network Automation CVE-2014-3418 command injection to create a sudo user and deliver a reverse Meterpreter…

iOS exploit tool that silences camera shutter sound on vulnerable devices (iOS 14-16.1.2) using MacDirtyCow vulnerability. Installed via TrollStore…

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

Bluetooth RFCOMM memory disclosure exploit framework for CVE-2025-13834, enabling unauthenticated OOB read of kernel/heap memory from 2.8 billion…

Zero-click iOS exploit chain leveraging CoreAudio heap corruption (CVE-2025-31200) and kernel escalation via AppleBCMWLAN (CVE-2025-31201), with…

Zero-click PNG-based exploit chain for iOS 18.2.1 chaining ImageIO, WebKit, and Core Media vulnerabilities to achieve sandbox escape, kernel-level…

Android 16 local privilege escalation exploit for realme RMX5200 using LD_PRELOAD-based preload.so chain to achieve temporary root access via…

Proof-of-concept exploit for CVE-2025-27840, a medium-severity vulnerability in ESP32 Bluetooth chips enabling unauthorized memory access via…

Exploit script for Novell ZENworks Mobile Management LFI vulnerability (CVE-2013-1081) with credential harvesting and remote code execution via…

Exploitation Framework for Embedded Devices

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

PoC exploits and testing framework for BlueBorne Bluetooth vulnerabilities, including Android RCE (CVE-2017-0781), Linux RCE (CVE-2017-1000251), and…

AndroRAT is a capability that can be used to inject a root exploit as a silent installation to perform a malicious task on the device. This AndroRAT…

Proof-of-concept exploit for CVE-2016-6584 that bypasses Samsung KNOX protections and roots Samsung Galaxy S6 devices via a kernel write-what-where…

EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over…

Bash script for Android device penetration testing via ADB, featuring 28 options and a Metasploit section for payload generation, remote control, and…