
RootMyVivo
One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU

One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU
Proof-of-concept exploit for CVE-2026-31431, a Linux kernel privilege escalation via AF_ALG authenc length check bypass, achieving root by modifying…

polkit pkexec Local Privilege Vulnerability to Add custom commands

Local privilege escalation exploit for CVE-2025-29824 targeting the Windows Common Log File System (CLFS) driver, providing proof-of-concept code for…

Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell

Exploit for CVE-2019-2215 to gain temporary root on Xiaomi MIUI devices, enabling bootloader unlock and system modifications.

Python exploit for CVE-2016-5195 (Dirty COW) enabling local privilege escalation on vulnerable Linux kernels.

Unitree G1 RCE PoC & Scripts (CVE-2026-76639 / CVE-2026-76640) technical details at boschko.ca/g1-ble-rce/

Security research: CVE-2026-43499 GhostLock on Huawei Nova 9 NAM-AL00 (SM7325, HMOS 4.2, kernel 5.4.86-qgki)

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process…

Single-stage exploit chain for CVE-2020-6418 (Chrome RCE) chained with Windows privilege escalation to SYSTEM, with build scripts and prebuilt…

GhostLock (CVE-2026-43499) adapter for 4.19.152-perf+ Android kernel

Local privilege escalation exploit for CVE-2022-2586 targeting Linux kernel 5.15.0-25 on Ubuntu 22.04, written in C and compiled with gcc.

Proof-of-concept exploit for CVE-2023-1281, a use-after-free vulnerability in the Linux kernel traffic control index filter (tcindex), demonstrating…

Modular Bluetooth Classic (BR/EDR) vulnerability testing framework with reconnaissance, exploit modules for 43 public attacks/CVEs, and structured…

Exploit tool targeting CVE-2026-43499 with automated payload delivery and vulnerability verification for penetration testing engagements.

Private exploit

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)