
Inferno
Open-source Apple Silicon device emulator based on QEMU, enabling iOS and iPhone hardware emulation with Secure Enclave Processor support for…

Open-source Apple Silicon device emulator based on QEMU, enabling iOS and iPhone hardware emulation with Secure Enclave Processor support for…

Open-source machine emulator and virtualizer for emulating iPhone 11 hardware, enabling security testing, firmware analysis, and iOS research without…

Jailbreak for A8 through A11, T2 devices, on iOS/iPadOS/tvOS 15.0, bridgeOS 5.0 and higher.

Lightweight TLS 1.3/DTLS 1.3 library with FIPS 140-3 validated cryptography, hardware entropy support, and post-quantum cipher suites for embedded,…

A privacy-preserving Raspberry Pi home security camera that uses advanced end-to-end encryption.

Captures raw 2G/3G/4G/5G cellular signaling from Qualcomm basebands via Diag, outputs PCAP for Wireshark, and exposes EFS/memory diagnostics.

Patched iOS SDKs restoring private framework symbols removed by Apple, enabling jailbreak tweak development and low-level iOS reverse engineering…

Exploit for CVE-2022-38694 that bypasses signature verification to unlock bootloader on Unisoc/Spreadtrum devices, executing code with BootROM…

Software-only SIM card emulator that runs without physical SIM hardware, provides PC/SC interfaces, and interoperates with phones via SIMtrace or any…

ARM64 ELF Virtual Machine Protection System

Collection of scripts for reversing Qualcomm Hexagon baseband / modem firmware

iPod Nano 7G bootrom exploit a bit too late

Proof-of-concept exploit for CVE-2015-6639, demonstrating privilege escalation in Qualcomm's QSEE TrustZone via PRDiag commands on Android devices.

a tool designed to help perform and visualize trace-driven cache attacks against software in the secure world of TrustZone-enabled ARMv8 cores

Tools for analyzing and reverse engineering MediaTek baseband firmware, including file extraction, symbol parsing, and Ghidra integration for modem…

Cert exploit for MTK devices.There is a logic flaw in MTK cert verification process.Similar to CVE-2023-20696.

My take on unlocking Xperia 5 SO-01M for p42 bootloader using CVE-2021-1931

An app that enables payload injection into a Switch console from an Android device by exploiting the CVE-2018-6242 vulnerability