
CVE-2024-0044
a vulnerability affecting Android version 12 & 13

a vulnerability affecting Android version 12 & 13

Demonstrates Android task hijacking (Strandhogg) via CVE-2020-0096, using crafted task launches to overlay target apps and intercept sensitive user…

An Android HW Attestation demo

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…


Educational Android lab for CVE-2023-31014 implicit intent hijacking

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

Android penetration testing tool for Kali linux

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Fermion, an electron wrapper for Frida & Monaco.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

The ARTful library for dynamically modifying the Android Runtime

The repo contains a series of challenges for learning Frida for Android Exploitation.

Binder Trace is a tool for intercepting and parsing Android Binder messages. Think of it as "Wireshark for Binder".


Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…