
WhatsRCE
This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

PoC Flask server for CVE-2026-22011 that serves a malicious iOS MDM enrollment profile over HTTP, enabling man-in-the-middle interception and device…

Exploit for CVE-2019-11932, a remote code execution vulnerability in WhatsApp via malicious GIF files. Includes proof-of-concept code and technical…

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

This is an exploit for CVE-2017-7047, Works on 10.3.2 and below.

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…

EvilDroid automates the exploitation of CVE-2024-0044, installing malicious payloads on a target device and extracting sensitive data. It features…

"A single malicious packet can own your device." — Android Security Team, Nov 2025

Public disclosure of CVE-2025-31200 – Zero-click RCE in iOS 18.X via AudioConverterService and malicious audio file.

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

Double-Free BUG in WhatsApp exploit poc.

Exploit helper for CVE-2019-11932 (WhatsApp GIF RCE) that calculates system() function and ROP gadget addresses for different devices to enable…

Proof of concept code to exploit flaw in adb that allowed opening network connections on the host to arbitrary destinations

AndroRAT is a capability that can be used to inject a root exploit as a silent installation to perform a malicious task on the device. This AndroRAT…