
two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal
Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

Educational Android lab for CVE-2023-31014 implicit intent hijacking

Comprehensive Android security vulnerability demonstrations featuring CVE-2017-13156 (Janus), broadcast receiver exploitation, external storage…

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

A python based tool for exploiting and managing Android devices via ADB


Static and dynamic Android application security analysis

fsp - Firestore Database Vulnerability Scanner Using APKs

Static analysis of APKs with regular expressions


Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

Utility to decrypt App Store apps on jailbroken iOS 11.x

iOS customization app powered by CVE-2022-46689. No jailbreak required.

iOS Application w/Implementation of CVE-2024-27804