
CVE-2019-8389
[CVE-2019-8389] An exploit code for exploiting a local file read vulnerability in Musicloud v1.6 iOS Application

[CVE-2019-8389] An exploit code for exploiting a local file read vulnerability in Musicloud v1.6 iOS Application

SSH brute-force tool targeting jailbroken iPhones with default 'alpine' password, featuring network scanning, wordlist-based cracking, and file…

Wrapper to maximize ISH iOS app capabilities without jailbreak

CVE-2011-0228 fix for older idevices/firmwares

iOS browser exploit for CVE-2020-9802, an old JIT bug.

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

Analysis of public exploits or my 1day exploits


Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…

Writeup and PoC of CVE-2024-27821, for education purposes.

Rust-based Tor library for Android and iOS, providing a standard API to integrate the Arti Tor runtime into mobile apps for private,…


Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox…

iOS Bluetooth PAN vulnerability that opens USB port 62078 and displays Ethernet icon without any adapter (€0). Apple sells a €89.95 adapter for the…

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…

CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

CVE-2024-25733 | ARC Browser Address Bar Spoofing PoC - iOS/iPadOS