
mobsfscan
mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

Patched sdks that include private framework tbds

A simple customization toolbox that utilizes CVE-2025-24203. Supports iOS 16.0 - iOS 18.3.2.

FairPlay decryptor (dump iPA) for iOS Application that running on macOS with SIP-enabled, using CVE-2025-24204. Support macOS 15.0-15.2

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

IDA plugin that resolves PPL calls to the actual underlying PPL function.

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

Jailbreak tweak to patch CVE-2025-31207, a bug that allows sandboxed applications to enumerate a user's installed apps

iOS app that does stuff with CVE-2025-24091

iOS/macOS library that exploits CVE-2023-41991 for signing iOS applications.

Proof-of-concept for CVE-2026-65343, an out-of-bounds read in AppleKeyStore that leaks kernel pointers to defeat KASLR on iOS 26.6. Includes ACM…

Coverage-guided kernel fuzzing framework that runs XNU as a userspace library and discovers vulnerabilities across BSD, Mach, virtual memory, and…

Radare2 and Frida better together.

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

an iOS kernel function hooking framework for checkra1n'able devices

AI-driven CLI for testing Android and iOS apps using natural language. Generates, runs, and fixes end-to-end tests on emulators/simulators with…

CVE-2018-4185: iOS 11.2-11.2.6 kernel pointer disclosure introduced by Apple's Meltdown mitigation.

This is POC for IOS 0click CVE-2025-43300