
Magisk
Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

Exploit code for CVE-2014-7920 and CVE-2014-7921 - code-exec in mediaserver up to Android 5.1

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Comprehensive Android security vulnerability demonstrations featuring CVE-2017-13156 (Janus), broadcast receiver exploitation, external storage…


This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

Simple POC for exploiting WhatsApp double-free bug in DDGifSlurp in decoding.c in libpl_droidsonroids_gif


double-free bug in WhatsApp exploit poc

Double-Free BUG in WhatsApp exploit poc.

Double-Free BUG in WhatsApp exploit poc.


Open-source instrumentation framework for Android apps and Java middleware, modifying code during on-device compilation via the ART compiler.…

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Android client for Prey: reliable device tracking and security tool

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House