
Triple_Fetch-Kernel-Creds
Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)

Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)

CVE-2022-46689

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then…

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

OS 12.0 & 12.1.2 - Jailbreak with CVE-2019-6225

iOS 15.1 kernel exploit POC for CVE-2021-30955

Slightly improved exploit of the CVE-2025-24203 iOS vulnerability by Ian Beer of Google Project Zero

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…


A demonstration of read write using cve-2025-43529 and userland PAC bypass on iOS 26.1

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

iOS 12.0 -> 12.1.2 Incomplete Osiris Jailbreak with CVE-2019-6225 by GeoSn0w (FCE365)

CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)

CVE-2018-4241: XNU kernel heap overflow due to bad bounds checking in MPTCP for iOS 11 - 11.3.1released by Ian Beer

CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)

Repository for the Smartphone Pentest Framework (SPF)

an iOS kernel function hooking framework for checkra1n'able devices

Patched sdks that include private framework tbds