
Android-Security-Masterclass
OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices.

A "plugin" for Android Java to allow asking the user about SSL certificates

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

Rust tool to detect cell site simulators on an orbic mobile hotspot

This project shows the kind of data a rogue iPhone application can collect.

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

[Android RAT] Remotely manage your android phone using PHP Interface

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

Automated SSL/TLS client security testing tool for detecting MITM vulnerabilities in thick clients, mobile apps, and network appliances.


Cve-2015-1538-1

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

A demonstration of read write using cve-2025-43529 and userland PAC bypass on iOS 26.1

CVE-2021-25337

Slightly improved exploit of the CVE-2025-24203 iOS vulnerability by Ian Beer of Google Project Zero