
CVE_2019_2215
Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

Kernel exploit for CVE-2026-43499 on Samsung Galaxy A17 achieving root via KDP bypass, KASLR recovery, and forged workqueue execution with persistent…

An Android HW Attestation demo

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

A curated list of awesome iOS application security resources.

Collections of my POCs for android vendor CVEs

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

Detect Tactics, Techniques & Combat Threats

A list of awesome penetration testing tools and resources.

Jailbreak for A8 through A11, T2 devices, on iOS/iPadOS/tvOS 15.0, bridgeOS 5.0 and higher.

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Mind-Maps of Several Things

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Next Generation SSLKillSwitch with much more support!

A curated list of hacking environments where you can train your cyber skills legally and safely

The ARTful library for dynamically modifying the Android Runtime

ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel