


CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29

CVE-2018-4330 POC for iOS

Proof-of-concept for a fixed PAC diversifier bypass in the tmpfs setxattr handler on iOS 26.6, demonstrating reachability of the vulnerable signing…

IOS audio buffer overflow CVE-2025-31200 POC

Proof-of-concept for CVE-2026-64788, a use-after-free in IOGPUFamily kernel extension on iOS 26.6, demonstrating exploitation via Metal texture…

Abusing CVE-2023-28206 to make something useful

Owning a tablet Amazon kept shutting down — CVE-2022-38181 write-up, four AI models, and a blog

CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability

8.4.1 Jailbreak using CVE-2016-4655 / CVE-2016-4656

oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming…

tfp0 based on CVE-2019-8591/CVE-2019-8605

Double-Free BUG in WhatsApp exploit poc.

PoC for CVE-2026-65343, an AppleKeyStore kernel OOB read on iOS 26.6 that leaks kernel pointers to defeat KASLR from a sandboxed app via…

CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)

simple poc for cve-2015-5932 / cve-2015-5847 / cve-2015-5864


Exploit iOS 11.2.x by ZIMPERIUM and semi-completed by me. Sandbox escapes on CVE-2018-4087.