
CVE-2026-20637-AppleSEPKeyStore-UAF
CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)

CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)

iblessing is an iOS security exploiting toolkit, it mainly includes application information gathering, static analysis and dynamic analysis. It can…

a Ghidra framework for iOS kernelcache reverse engineering

Web-based Source Code Vulnerability Scanner

AI-driven vulnerability discovery and live validation

CVE-2018-4280: Mach port replacement vulnerability in launchd on iOS 11.2.6 leading to sandbox escape, privilege escalation, and codesigning bypass.

This is POC for IOS 0click CVE-2025-43300

Proof-of-concept and write-up for the CVE-2022-32832 vulnerability patched in iOS 15.6


A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

Apple OS X/iOS SSL flaw demonstration

Non-decompiling iOS/Android app vulnerability scanner (DC25 demo lab, CB17)

Extraction of iMessage Data via XSS

PoC for CVE-2026-28990, an ImageIO bug patched in iOS/macOS 26.5

Slightly improved exploit of the CVE-2025-24203 iOS vulnerability by Ian Beer of Google Project Zero

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger…

POC: Heap buffer overflow in the networking code in the XNU operating system kernel