
EVABS
An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

Intentionally vulnerable Android application.

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Proof-of-concept demonstrating CVE-2026-0023, an Android Update Ownership trust bypass that suppresses the ownership warning during app updates.…

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

Intentionally vulnerable Android banking app for practicing mobile security testing, featuring root detection, anti-debugging, SSL pinning, and…

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

Bootloader unlock using CVE-2022-38694 for Retroid Pocket 3+

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…

A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis

The repo contains a series of challenges for learning Frida for Android Exploitation.

Android security guides, roadmap, docs, courses, write-ups, and teryaagh.

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

How to Install OpenClaw on an Android Phone and Control It via WhatsApp

A container-based framework to enable the integration of mobile components in security training platforms