
MASTG-Hacking-Playground
Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

Proof-of-concept demonstrating CVE-2026-0023, an Android Update Ownership trust bypass that suppresses the ownership warning during app updates.…

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

Proof-of-concept exploit for CVE-2019-2215 (Bad Binder) targeting Android 10 x86_64 emulator. Designed for isolated kernel exploitation research and…

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

Educational Android lab for CVE-2023-31014 implicit intent hijacking

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

Free hands-on digital forensics labs for students and faculty

Web and mobile application security training platform

A curated list of awesome iOS application security resources.

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Simple customization toolbox, utilizing CVE-2025-24203. Supports iOS 16.0 - iOS 18.3.2.

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

My personal hacklab, create your own.

Exploit basado en vulnerabilidades criticas Bluetooth (CVE-2023-45866, CVE-2024-21306)

android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users

Proof-of-concept exploit for CVE-2026-52199: unauthenticated remote code execution via exposed ADB daemon on UZ801 4G LTE router. Includes…