
DVIA-v2
Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessary resources for APT repositories.

CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.

Modernized Python 3 exploit PoC for CVE-2016-4631 targeting iOS devices. Features network scanning, malformed IP/TCP payload generation, and packet…

iOS platform security & anti-tampering Swift library

A privacy-focused iOS app that raises awareness about what native apps can see

A curated list of awesome iOS application security resources.

Simple customization toolbox, utilizing CVE-2025-24203. Supports iOS 16.0 - iOS 18.3.2.

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

itunesstored & bookassetd sbx escape

This project shows the kind of data a rogue iPhone application can collect.

Deterministic kernel exploit based on CVE-2023-32434.

This is POC for IOS 0click CVE-2025-43300

Proof-of-concept and write-up for the CVE-2022-32832 vulnerability patched in iOS 15.6

All-in-one macOS binary analysis: Mach-O parsing, ARM64 disassembly, code signatures, and debugging.

research on finding the bug and fix of CVE-2026-84616 and CVE-2026-84607

IOS audio buffer overflow CVE-2025-31200 POC

Workaround for the vulnerability identified by TWSL2011-007 or CVE-2008-0228 - iOS x509 Certificate Chain Validation Vulnerability