
frameworks_av_AOSP10_r33_CVE-2021-0509
Android media framework vulnerability fix for CVE-2021-0509, addressing a use-after-free in audio flinger to prevent local privilege escalation.

Android media framework vulnerability fix for CVE-2021-0509, addressing a use-after-free in audio flinger to prevent local privilege escalation.

CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

Unlock the bootloader of any exploitable device vulnerable to CVE-2021-30327

Minimal PoC for a Samsung SveService buffer overflow, demonstrating an out-of-bounds write via Binder to crash the Android system service without…

GhostLock (CVE-2026-43499) for the Galaxy S26

Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

Simple script to add a new, unrestricted user on devices with Family Link by abusing CVE-2025-32324 (pre September patch)

Jake Jame's proof of concept wrapped into an iOS app for CVE-2021-30955

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

A MediaTek modem input validation issue can cause a system crash (remote DoS) when a UE connects to a rogue base station controlled by an attacker…

Proof-of-concept IPA for CVE-2021-30955, targeting iOS 15.0-15.2b1, demonstrating a local privilege escalation vulnerability.

Android framework patch for CVE-2021-0705, addressing a privilege escalation vulnerability in the Android operating system.

Android Bluetooth package with modifications addressing CVE-2021-0329, a critical remote code execution vulnerability in Bluetooth. Provides patched…

Proof-of-concept for CVE-2026-7671, demonstrating OTP brute-force on Tornet Scooter Android app due to missing rate limiting on /TwoFactor endpoint.

CVE-2025-48595 Android Framework Integer Overflow PoC - 优化版