
CVE-2024-23700
PoC for CVE-2024-23700, Android slient privilege escalation allow to read/write contacts, SMS, calendar, call log and voicemail, make outgoing calls…

PoC for CVE-2024-23700, Android slient privilege escalation allow to read/write contacts, SMS, calendar, call log and voicemail, make outgoing calls…

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

iOS customization app powered by CVE-2022-46689. No jailbreak required.

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

Exploit I discovered in October of 2022 with androids Package manager binary (pm) and the way it handled debugging flags, patched out by march 2023.…

Ghidra is a software reverse engineering (SRE) framework

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection

Python script to inject existing Android applications with a Meterpreter payload.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit


a vulnerability affecting Android version 12 & 13

CVE-2017-2370

Blog Pribadi

(deprecated) Android application vulnerability analysis and Android pentest tool

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Robust Frida-based tool to dump decrypted iOS apps as .ipa from a jailbroken device supports App Store, sideloaded and system.