
ghostlock-x200-app
vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)

vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)

PoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

a vulnerability affecting Android version 12 & 13

Android Application Task Hijacking Aka Strandhogg Attack Exploit

An Android HW Attestation demo

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Walk through CVE-2023-41898: exploit an unvalidated deep link in Home Assistant Android to load arbitrary URLs in a privileged WebView and leak a…

Educational Android lab for CVE-2023-31014 implicit intent hijacking

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

Android penetration testing tool for Kali linux

Unofficial frida extension for VSCode

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Fermion, an electron wrapper for Frida & Monaco.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…