
Magisk
Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

Curated index of game security research: anti-cheat internals, DMA attacks, reverse engineering, kernel/mobile protections, and graphics API hooking…

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting

itunesstored & bookassetd sbx escape

The above investigation of the ES file browser security weakness allows us to see the issue in its entirety

Collections of my POCs for android vendor CVEs

Extracts and decrypts the 4-digit restriction passcode from iPhone backups on Windows machines, enabling recovery of device access controls.

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

Burp Plugin to decrypt AES encrypted traffic on the fly

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Collection of quality safety articles. Awesome articles.

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

PoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta

Proof of concept code to exploit flaw in adb that allowed opening network connections on the host to arbitrary destinations

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…