
TEE-reversing
A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Bash script to build your own system.prop

BootStomp: a bootloader vulnerability finder

CVE-2025-21479 proof-of-concept, I think

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.

Glass - a fast and free IDA Pro alternative

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

Low-level kernel modules and device tree source for the OnePlus 11 (sm8550), enabling hardware bring-up, driver analysis, and embedded system…

Cert exploit for MTK devices.There is a logic flaw in MTK cert verification process.Similar to CVE-2023-20696.

Root your Galaxy using CVE-2026-43499

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Adaptation of CVE-2023-6241 for Google Pixel 7 from Google Pixel 8 taken from securitylab/SecurityExploits/Android/Mali/CVE_2023_6241

Python utility to check if Android verified boot images (vbmeta) are signed with publicly known test keys, identifying misconfigurations in release…

Bootloader unlock (CVE-2022-38694) & root guide for Realme C53 / RMX3760 (Unisoc T612)

Unlock Bootloader for Itel S23 (S665L) / Unisoc T606 using CVE-2022-38694

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko.…

Translated strings for World Conqueror 4 (RU)