
Mobile-Security-Framework-MobSF
Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Proof-of-concept exploit for Apple SSL/TLS verification vulnerability (CVE-2014-1266) in iOS and OS X, demonstrating HTTPS interception via a proxy…

Proof-of-concept exploit for CVE-2016-1764 demonstrating XSS in Apple's OS X iMessage client to recover plaintext chat history and attachments via…

Zero-click PNG-based exploit chain for iOS 18.2.1 chaining ImageIO, WebKit, and Core Media vulnerabilities to achieve sandbox escape, kernel-level…

Exploit code for CVE-2019-8389, a local file read vulnerability in Musicloud iOS v1.6, leveraging the Wi-Fi transfer service to read arbitrary files…

iOS browser exploit for CVE-2020-9802, an old JIT bug.

CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability

Proof-of-Concept exploit for CVE-2025-14174 (EUVD-2025-203113) - Memory corruption in ANGLE allowing out-of-bounds access and RCE in web browsers.…

Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…

PoC exploit for WebKit CVE-2023-41993 providing arbitrary read/write primitives via JavaScriptCore memory corruption, delivered to Safari through a…

Details a zero-click iOS exploit chain using WebKit and Core Media flaws: RCE, sandbox escape, kernel privilege escalation, persistence, and device…

Proof-of-concept exploit for CVE-2024-25733 demonstrating address bar spoofing in ARC Browser on iOS/iPadOS using JavaScript-based navigation…

JavaScript payload exploiting WebKit Use-After-Free (CVE-2025-43529) and ANGLE (CVE-2025-14174) on Apple Silicon, bypassing memory tagging via WebGL…

Proof-of-concept exploit for a cross-site scripting (XSS) vulnerability in Microsoft Outlook for iOS, enabling email-based spoofing attacks and…

Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)

Exploit for iOS Safari remote code execution vulnerability CVE-2025-43529, leveraging convergent time theory for enhanced reliability.

Proof-of-concept exploits and technical write-up for CVE-2021-30862, a one-click RCE in Apple iOS iTunes U, including crash PoCs and JavaScript…

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in the URVE Smart Office iOS app, with CVE details, impact analysis, and…