
CVE-2019-6447
The above investigation of the ES file browser security weakness allows us to see the issue in its entirety

The above investigation of the ES file browser security weakness allows us to see the issue in its entirety

Extracts and decrypts the 4-digit restriction passcode from iPhone backups on Windows machines, enabling recovery of device access controls.

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

Python exploit for CVE-2019-6447 enabling arbitrary file read on ES File Explorer 4.1.9.7.4 for Android. Demonstrates mobile vulnerability…

Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

Scanning APK file for URIs, endpoints & secrets.

Android Remote Access Trojan

Hand-crafted Frida examples

All-in-One malware analysis tool.

Builds flashable installer ZIPs that deploy a mobile penetration-testing environment on Android, including kernel boot patching, rootfs integration,…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Crack ios Restriction PassCode in Python

CAFest nethunter kernel based on LA.UM.9.1.r1-11900-SMXXX0.0 with latest upstream-f2fs-stable-linux-4.14.y merged, bb and perf focused. | Force push…

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

Cloud-based Android monitoring tool with GPS tracking, microphone recording, SMS/call logging, live notification capture, file explorer, and built-in…