
AuroraStore
Open-source Android client for browsing and downloading apps from Google Play with anonymous login, device/locale spoofing, and tracker detection.

Open-source Android client for browsing and downloading apps from Google Play with anonymous login, device/locale spoofing, and tracker detection.

vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)

PoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

Extracts decrypted IPA files from jailbroken iOS devices using Frida for reverse engineering, security analysis, and mobile app pentesting.

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

An updated Frida iOS dump tool supporting the latest Frida 17.5.2 APIs

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Command-line tool that allows searching and downloading app packages (known as ipa files) for iOS, iPadOS, tvOS, and visionOS from the App Store.


Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

a vulnerability affecting Android version 12 & 13

Android Application Task Hijacking Aka Strandhogg Attack Exploit

An Android HW Attestation demo

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Walk through CVE-2023-41898: exploit an unvalidated deep link in Home Assistant Android to load arbitrary URLs in a privileged WebView and leak a…