
pbtk
A toolset for reverse engineering and fuzzing Protobuf-based apps

A toolset for reverse engineering and fuzzing Protobuf-based apps

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

PulseAPK Core: Cross-Platform tool for working with APK files: Decompilation, Analysis, Building

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Proof-of-concept exploit for CVE-2025-31931 demonstrating arbitrary shared library loading in Intel ITT API on Android, affecting OpenCV 4.10.

Intentionally vulnerable Android application.

Collections of my POCs for android vendor CVEs


Analyzes and demonstrates CVE-2020-0381, a vulnerability in the Android sonivox audio engine, providing binary analysis and exploitation research for…


Android Wi-Fi vulnerability research repository containing patched wpa_supplicant source for CVE-2021-0326, enabling analysis and testing of the…

Grammar-guided evolutionary fuzzer for dynamic analysis of AT command interfaces on Android smartphones via Bluetooth and USB, uncovering DoS,…

Exploit for CVE-2020-6514 targeting WebRTC SCTP memory corruption in Android applications. Uses Frida to hook native functions and alter SCTP packets…

Proof-of-concept exploit for CVE-2019-2107, demonstrating remote code execution via crafted HEVC video on Android media framework. Includes crash…

POC for CVE-2015-6620, AMessage unmarshal arbitrary write