
Damn-Vulnerable-Android-Components
An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

Proof-of-concept demonstrating CVE-2026-0023, an Android Update Ownership trust bypass that suppresses the ownership warning during app updates.…

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

Educational Android lab for CVE-2023-31014 implicit intent hijacking

Walk through CVE-2023-41898: exploit an unvalidated deep link in Home Assistant Android to load arbitrary URLs in a privileged WebView and leak a…

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamı

Proof-of-concept exploit for CVE-2019-2215 (Bad Binder) targeting Android 10 x86_64 emulator. Designed for isolated kernel exploitation research and…

Comprehensive Android security vulnerability demonstrations featuring CVE-2017-13156 (Janus), broadcast receiver exploitation, external storage…

PoC for CVE-2024-23700, Android slient privilege escalation allow to read/write contacts, SMS, calendar, call log and voicemail, make outgoing calls…

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

2024年信息安全工程师、2024InformationSecurityEngineer

Lab Exploit (CVE-2021-521): App uses Java reflection to access Android system components, retrieving a list of all installed apps. Reflection…

Android Task Hijacking (CVE-2021-33699) exploit practice app with attacker and victim components for hands-on mobile security training.