


Magisk module for Android 14 that adds user-installed CA certificates to the system's Conscrypt trust store, enabling HTTPS interception with proxy…

Static and dynamic Android application security analysis

Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.

LD_PRELOAD magic for Android's AssetManager

PulseAPK is a WPF frontend for apktool and uber-signer with drag-and-drop support, live decompilation output, smali analysis, and integrated APK…

A command-line utility to exploit Android Zygote injection (CVE-2024-31317)

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

Exfiltrate sensitive user data from apps on Android 12 and 13 using CVE-2024-0044 vulnerability remotely

An Android HW Attestation demo

Frida toolkit that bypasses SSL/TLS certificate pinning on Android apps, hooking Java TrustManager, OkHttp, Conscrypt, and native OpenSSL/BoringSSL…

PoC for CVE-2024-23700, Android slient privilege escalation allow to read/write contacts, SMS, calendar, call log and voicemail, make outgoing calls…

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

PoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

A complete Android ImGui menu template project.

Mobile Application Vulnerability Detection

PoC Exploit for AOSP UserDictionary Content Provider (CVE-2018-9375)