
CVE-2026-28858
Technical analysis of CVE-2026-28858, a critical buffer overflow in Apple iOS/iPadOS kernel, including exploit flow, mitigation, and defensive coding…

Technical analysis of CVE-2026-28858, a critical buffer overflow in Apple iOS/iPadOS kernel, including exploit flow, mitigation, and defensive coding…

A curated list of awesome iOS application security resources.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Every Apple Platform Security Guide

Curated collection of iOS kernel and userland exploit PoCs and writeups for in-the-wild and researched CVEs, including binary-diffed vulnerability…


Simulated macOS/iOS XPC service vulnerable to NSKeyedUnarchiver deserialization, plus exploit demonstration and crafted plist payload for RCE via…

Dive into CFF font and coincidently learn about a bof in cff parsing from some jailbreak. just for fun

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

itunesstored & bookassetd sbx escape

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

This project shows the kind of data a rogue iPhone application can collect.

iOS Bluetooth PAN vulnerability that opens USB port 62078 and displays Ethernet icon without any adapter (€0). Apple sells a €89.95 adapter for the…

A collection of resources for OSX/iOS reverse engineering.

Modernized Python 3 exploit PoC for CVE-2016-4631 targeting iOS devices. Features network scanning, malformed IP/TCP payload generation, and packet…

This uses CVE-2025-43407 as exploit and still testing working not gauranteed.

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

Conceptual proof-of-concept for CVE-2024-44258, an iOS symlink vulnerability during backup restoration. Demonstrates the exploitation mechanism for…