
zero-click-exploit-analysis
CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.

CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.

Public disclosure for CVE-2026-43655 AppleM2ScalerCSCDriver use-after-free

iOS app that does stuff with CVE-2025-24091

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

Proof-of-concept IPA for CVE-2021-30955, targeting iOS 15.0-15.2b1, demonstrating a local privilege escalation vulnerability.

CVE-2017-2370

CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)

I do some tweaking for iOS from 16.0 to 16.1.2 based on MacDirtyCow (CVE-2022-46689) exploit.

webkit_refraction.js (The 33-Layer WebGL Payload) This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It…

Jake Jame's proof of concept wrapped into an iOS app for CVE-2021-30955

CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)

Block "itms scheme" / fix CVE-2021-1748

iOS/macOS library that exploits CVE-2023-41991 for signing iOS applications.

iOS Application w/Implementation of CVE-2024-27804

Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2)