
mariana-trench
A security focused static analysis tool for Android and Java applications.

A security focused static analysis tool for Android and Java applications.

FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Android AOSP 10 framework base repository patched for CVE-2021-39696, providing a reference for vulnerability analysis and exploitation of Android…

iblessing is an iOS security exploiting toolkit, it mainly includes application information gathering, static analysis and dynamic analysis. It can…

Android framework base repository containing patches or analysis for CVE-2022-20493, addressing a security vulnerability in the Android platform.

Exploit or analysis code for CVE-2023-21118 in Android frameworks_native, targeting AOSP 10 r33. Provides vulnerability research and exploitation for…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

iOS platform security & anti-tampering Swift library

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

All-in-one macOS binary analysis: Mach-O parsing, ARM64 disassembly, code signatures, and debugging.

Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…

Technical analysis of CVE-2026-28858, a critical buffer overflow in Apple iOS/iPadOS kernel, including exploit flow, mitigation, and defensive coding…

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in the URVE Smart Office iOS app, with CVE details, impact analysis, and…

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

A Hacker's E-learning App for Tamil People