
CVE-2026-43805-PoC
CVE-2026-43805 IOKit IODMACommand race analysis and proof of concept

CVE-2026-43805 IOKit IODMACommand race analysis and proof of concept
Proof-of-concept trigger for CVE-2024-27815, an XNU kernel heap buffer overflow in sbconcat_mbufs() reachable via AF_UNIX datagram sockets, causing…

PoC for CVE-2026-65343, an AppleKeyStore kernel OOB read on iOS 26.6 that leaks kernel pointers to defeat KASLR from a sandboxed app via…

iOS Messages JPEG XL delivery-surface probe and patch-diff notes for CVE-2026-28956.

Proof-of-concept for CVE-2026-64788, a use-after-free in IOGPUFamily kernel extension on iOS 26.6, demonstrating exploitation via Metal texture…

Proof-of-concept for a fixed PAC diversifier bypass in the tmpfs setxattr handler on iOS 26.6, demonstrating reachability of the vulnerable signing…

Proof-of-concept for CVE-2026-65343, an out-of-bounds read in AppleKeyStore that leaks kernel pointers to defeat KASLR on iOS 26.6. Includes ACM…

Proof-of-concept for an out-of-bounds write in XNU's vfs_attr_pack_internal (getattrlist) on iOS 26.6, demonstrating kernel heap corruption and…

Boot and manage virtual iPhones on Apple Silicon with firmware patching, jailbreak variants, and security research features for iOS testing and…

desc_race exploit for iOS 15.0 - 15.1.1 (with stable kernel r/w primitives) (CVE-2021-30955)

Jake Jame's proof of concept wrapped into an iOS app for CVE-2021-30955

CVE-2021-30955 iOS 15.1.1 POC for 6GB RAM devices (A14-A15)

CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)

iOS app to check device compatibility with CVE-2021-30937 vulnerability, displaying alerts and popups during the process.

PoC exploit for WSUS CVE-2025-59287 using XML deserialization to achieve a Windows reverse shell via SOAP and ObjectDataProvider.

Proof-of-concept IPA for CVE-2021-30955, targeting iOS 15.0-15.2b1, demonstrating a local privilege escalation vulnerability.

Proof-of-concept exploit for CVE-2025-54957, an out-of-bounds write in Dolby's DDPlus Unified Decoder, demonstrating a 0-click crash on Android via…