
CyberMeowfiaNS
The next stage of CyberMeowfil (CVE-2026-43499 and 43074),Possibly biased toward vivo devices?

The next stage of CyberMeowfil (CVE-2026-43499 and 43074),Possibly biased toward vivo devices?

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (COMPLETED)

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

An NFC research toolkit application for Android

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari

Poc for CVE-2024-36971

Image-based Android malware detection framework tackling obfuscation and concept drift. Includes curated datasets and Python code for training…

A bug trigger for CVE-2023-20938 for Android Binder.

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.

Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…

Detailed technical analysis and proof-of-concept for Android CVE-2022-20474, a Bundle mismatch vulnerability exploiting LazyValue with negative…

Proof-of-concept and writeup for bypassing the initial patch of CVE-2024-0044, an Android framework vulnerability enabling privilege escalation from…

An automatic obfuscation tool for Android apps that works in a black-box fashion, supports advanced obfuscation features and has a modular…

Proof of concept for CVE-2021-25461, a vulnerability in Android Unix domain sockets, demonstrating exploitation techniques and providing analysis for…