
CVE-2024-0044
a vulnerability affecting Android version 12 & 13

a vulnerability affecting Android version 12 & 13

Fermion, an electron wrapper for Frida & Monaco.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

LD_PRELOAD magic for Android's AssetManager


Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.

app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

Python script to inject existing Android applications with a Meterpreter payload.

Damn Vulnerable Hybrid Mobile App (DVHMA) is an hybrid mobile app (for Android) that intentionally contains vulnerabilities.

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

A tool that automates the mundane tasks of pentesting Android apps. It uses APKTool and Dex2Jar.

fsp - Firestore Database Vulnerability Scanner Using APKs

Android APK unpacker that dumps DEX files from running or installed apps on Android 5.0–12 without root, Xposed, or Frida, supporting deep unpacking…