
FireStorePwn
fsp - Firestore Database Vulnerability Scanner Using APKs

fsp - Firestore Database Vulnerability Scanner Using APKs

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

A native APK and DEX decompiler written in Rust

Android deeplink, Intent, and WebView bridge assessment helper for ethical hacking

PoC and red team app for CVE-2026-28576, a zero-permission SQL injection in the Android Contacts Provider enabling full contacts database…

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

Unofficial frida extension for VSCode

Fermion, an electron wrapper for Frida & Monaco.

DEX → Java decompiler in Rust — fast, progressive analysis, bilingual CLI

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

The repo contains a series of challenges for learning Frida for Android Exploitation.

The ARTful library for dynamically modifying the Android Runtime

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…