
device-activity-tracker
A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

How to Install OpenClaw on an Android Phone and Control It via WhatsApp

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

Hands-on challenges for learning how to reverse engineer Flutter applications.

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13. This repo demonstrates how to exploit…

Python simulation of CVE-2026-22012, showing how a missing Final-Unit-Indication in Diameter Credit-Control allows unlimited quota and service bypass…

Proof-of-concept and writeup showing how to retrieve Wi-Fi SSID/password from a D-Link Komfy smart switch over BLE by reversing the iOS app’s custom…

NOTICE This repository contains the public FTC SDK for the SKYSTONE (2019-2020) competition season. If you are looking for the current season's FTC…

Cross-platform GUI written in Rust using ADB to debloat non-rooted Android devices. Improve your privacy, the security and battery life of your…

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

itunesstored & bookassetd sbx escape

Blue Pigeon is a Bluetooth-based data exfiltration and proxy tool to enable communication between a remote Command and Control (C2) server and a…

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

CVE-2022-46718: an app may be able to read sensitive location information.

Adaptation of CVE-2023-6241 for Google Pixel 7 from Google Pixel 8 taken from securitylab/SecurityExploits/Android/Mali/CVE_2023_6241