
SSH-KILLv2
SSH brute-force tool targeting jailbroken iPhones with default 'alpine' password, featuring network scanning, wordlist-based cracking, and file…

SSH brute-force tool targeting jailbroken iPhones with default 'alpine' password, featuring network scanning, wordlist-based cracking, and file…

CVE-2023-40429: An app may be able to access sensitive user data.

Jake Jame's proof of concept wrapped into an iOS app for CVE-2021-30955

Write-up and proof of concepts for CVE-2021-30862, 1-click RCE bug in iOS iTunes U

Technical analysis and exploit demonstration of CVE-2022-32898, a kernel memory corruption vulnerability in Apple Neural Engine driver, with detailed…

Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari

# CVE-2026-28995 Proof of Concept for CVE-2026-28995 — Path Traversal vulnerability in App Intents on iOS 26.4.2 and below.

iOS Application w/Implementation of CVE-2024-27804

Curated proof-of-concept exploits for real-world CVEs affecting iOS, macOS, Chrome Renderer, and Steam clients, with version-specific targets and…

Proof-of-concept for CVE-2023-41992, a macOS kernel vulnerability, demonstrating exploitation techniques and providing a patch analysis.

CVE-2021-30955 iOS 15.1.1 POC for 6GB RAM devices (A14-A15)

Analysis and PoC for CVE-2025-14174 - ANGLE Metal OOB write (iOS Safari, macOS Chrome)

Patch iOS SSL vulnerability (CVE-2014-1266)

Kernel crash caused by out-of-bounds write in Apple's ICMP packet-handling code (CVE-2018-4407)

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

IDA plugin that resolves PPL calls to the actual underlying PPL function.

Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…