

Mobile application testing toolkit

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)


Crash macOS and iOS devices with one packet

iOS Syscall Explorer for IDA 9.X

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

Proof-of-concept exploit for a heap over-read in libarchive RAR v4 filter (CVE-2025-5915) with ASan reproduction, encoder, and on-device iOS 18.5…

Public disclosure for CVE-2026-43655 AppleM2ScalerCSCDriver use-after-free

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Extraction of iMessage Data via XSS

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox…

