
iDescriptor
A free, open-source, and cross-platform iDevice management tool

A free, open-source, and cross-platform iDevice management tool

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

Now you can mirror and control your jailbroken iPhone over USB

Kernel info leak Proof of Concept patched in iOS 26.4 / macOS 26.4

Robust Frida-based tool to dump decrypted iOS apps as .ipa from a jailbroken device supports App Store, sideloaded and system.

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

open-source jailbreaking tool for many iOS devices

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

CVE-2023-40429: An app may be able to access sensitive user data.

CVE-2022-46718: an app may be able to read sensitive location information.

Static analysis tool for iOS applications that extracts links, API keys, subdomains, binary info, linked libraries, and strings to aid mobile…

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

Binary & scripts associated with "The Poor Man's Obfuscator" presentation

iOS gamed exploit (fixed in 15.0.2)