
CVE-2026-20687-AppleJPEGDriver-UAF
CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

Collects macOS and iOS artifacts to build timelines of network activity, cross-device identity, and physical location correlation for reconnaissance…

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

Command-line tool that allows searching and downloading app packages (known as ipa files) for iOS, iPadOS, tvOS, and visionOS from the App Store.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

PoC Flask server for CVE-2026-22011 that serves a malicious iOS MDM enrollment profile over HTTP, enabling man-in-the-middle interception and device…

An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

iOS gamed exploit (fixed in 15.0.2)

iOS 15 0-day exploit (still works in 15.0.2)

open-source jailbreaking tool for many iOS devices

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger…

on Mac 10.12.2

Security profiling for blackbox iOS

iOS Bluetooth PAN vulnerability that opens USB port 62078 and displays Ethernet icon without any adapter (€0). Apple sells a €89.95 adapter for the…

Broadpwn bug (CVE-2017-9417)