
CVE-2024-0044
a vulnerability affecting Android version 12 & 13

a vulnerability affecting Android version 12 & 13

Demonstrates Android task hijacking (Strandhogg) via CVE-2020-0096, using crafted task launches to overlay target apps and intercept sensitive user…

An Android HW Attestation demo

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…


Educational Android lab for CVE-2023-31014 implicit intent hijacking

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

A curated list of awesome iOS application security resources.

Android penetration testing tool for Kali linux

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Fermion, an electron wrapper for Frida & Monaco.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Next Generation SSLKillSwitch with much more support!

The ARTful library for dynamically modifying the Android Runtime

The repo contains a series of challenges for learning Frida for Android Exploitation.

Binder Trace is a tool for intercepting and parsing Android Binder messages. Think of it as "Wireshark for Binder".