
CVE-2021-38297-Go-wasm-Replication
Educational proof-of-concept replicating CVE-2021-38297, a Go WASM buffer overflow leading to stored XSS. Includes vulnerable app setup, exploit…

Educational proof-of-concept replicating CVE-2021-38297, a Go WASM buffer overflow leading to stored XSS. Includes vulnerable app setup, exploit…

Unified Security Research Tool

Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.

An automatic obfuscation tool for Android apps that works in a black-box fashion, supports advanced obfuscation features and has a modular…

Proof-of-concept and writeup for bypassing the initial patch of CVE-2024-0044, an Android framework vulnerability enabling privilege escalation from…

Open-source instrumentation framework for Android apps and Java middleware, modifying code during on-device compilation via the ART compiler.…

Android App Pin Security Issue Allowing Unauthorized Payments via Google Wallet

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

Educational proof-of-concept demonstrating a SQL injection vulnerability in Android 17's Contacts Provider, allowing a zero-permission app to…

Open-source intelligence investigation into Meta's multi-channel lobbying campaign for the App Store Accountability Act, tracing dark money flows,…

Documented reflected XSS vulnerability (CVE-2025-55998) in Mezereon's Smart Search and Filter app for Shopify and BigCommerce, with proof-of-concept…

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in the URVE Smart Office iOS app, with CVE details, impact analysis, and…

The Redexer binary instrumentation framework for Dalvik bytecode

CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (COMPLETED)

reverse engineering Gemini's SynthID detection

Proof-of-concept demonstrating command injection in Windows Notepad via crafted Markdown links, enabling remote code execution. Includes attack…

An NFC research toolkit application for Android

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices