
CVE_2019_2215
Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

GhostLock CVE-2026-43499 research for Galaxy S26 (SM-S942U1/m1q): SELinux Permissive achieved, KASLR + tracefs port, uid=0 boundary documented

Kernel exploit for CVE-2026-43499 on Samsung Galaxy A17 achieving root via KDP bypass, KASLR recovery, and forged workqueue execution with persistent…

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

UNISOC BootROM/FDL flasher for macOS: patched spd_dump with CVE-2022-38694 exec_addr2, protocol reference, partition rules, backup verification…

Python-based exploit for Android's Janus CVE-2017-13156, demonstrating APK signature bypass by appending a DEX payload to signed applications.

Android kernel exploit for Samsung Galaxy S22 that gains kernel-domain root via CVE-2026-43499, with SELinux permissive, device-specific kallsyms,…

CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)

Kernel privilege escalation research archive for CVE-2026-43499 (GhostLock) on Honor Magic6 Pro, documenting exploitation analysis, reverse…

Exploit kit for Exynos 9830 bootROM that delivers signed-boot bypass, custom key injection, and memory-dump payloads for Samsung SM-G985F devices.

Patches Android ARMv8.3 kernel binaries to disable driver signature verification, enabling custom kernel module loading for development and security…

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

CVE-2025-21479 (Qualcomm Adreno GPU) reproduction notes for vivo iQOO 11 Pro (PD2254) - authorized research

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

CVE-2026-43499 (GhostLock) rtmutex remove_waiter() UAF local-root PoC adapted for Qualcomm Android 4.19 kernels (Redmi K40 / Snapdragon 870 class),…