
CVE-2022-32832
Proof-of-concept and write-up for the CVE-2022-32832 vulnerability patched in iOS 15.6

Proof-of-concept and write-up for the CVE-2022-32832 vulnerability patched in iOS 15.6

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

iOS browser exploit for CVE-2020-9802, an old JIT bug.

oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming…

Simulated macOS/iOS XPC service vulnerable to NSKeyedUnarchiver deserialization, plus exploit demonstration and crafted plist payload for RCE via…

Conceptual proof-of-concept for CVE-2024-44258, an iOS symlink vulnerability during backup restoration. Demonstrates the exploitation mechanism for…

Educational exploit for CVE-2017-7117, a type-confusion and use-after-free vulnerability in iOS 10.3.4 JavaScriptCore, demonstrating memory spraying…

Dive into CFF font and coincidently learn about a bof in cff parsing from some jailbreak. just for fun

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in the URVE Smart Office iOS app, with CVE details, impact analysis, and…

AI powered security analysis extension for Mobile Security Framework MobSF

Open-source iOS messenger providing end-to-end encrypted text, voice, and video calls via the Signal Protocol, with no analytics or telemetry…


iOS <=26.0.1 DarkSword Kernel Exploit reimplemented in Objective-C

AI-driven vulnerability discovery and live validation


A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)

tfp0 based on CVE-2019-8591/CVE-2019-8605