
awesome-mobile-security
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…

A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis

Intentionally vulnerable Android banking app for practicing mobile security testing, featuring root detection, anti-debugging, SSL pinning, and…

Intentionally vulnerable Android application.

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

A flexible playground for Android CTF challenges.

Hands-on challenges for learning how to reverse engineer Flutter applications.

The repo contains a series of challenges for learning Frida for Android Exploitation.

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

A container-based framework to enable the integration of mobile components in security training platforms

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

Proof-of-concept demonstrating CVE-2026-0023, an Android Update Ownership trust bypass that suppresses the ownership warning during app updates.…

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

Educational Android lab for CVE-2023-31014 implicit intent hijacking

Walk through CVE-2023-41898: exploit an unvalidated deep link in Home Assistant Android to load arbitrary URLs in a privileged WebView and leak a…

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.