
ABrake27
iOS 27 kernelcache RE: SEP dispatch map, AMFI diff, Ghidra workflow

iOS 27 kernelcache RE: SEP dispatch map, AMFI diff, Ghidra workflow

A demonstration of read write using cve-2025-43529 and userland PAC bypass on iOS 26.1

PoC demonstrating dyld as a PAC signing oracle via hand-crafted Mach-O chained fixups on arm64e, achieving controlled PAC-valid pointer writes and…

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…

webkit_refraction.js (The 33-Layer WebGL Payload) This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It…

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then…

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox…

IOS audio buffer overflow CVE-2025-31200 POC

Write-up and proof of concepts for CVE-2021-30862, 1-click RCE bug in iOS iTunes U


Safari 1day RCE Exploit

poc for CVE-2023-40448 (under construction) ,This could probably be a piece for a jailbreak

Untethered + Unsandboxed code execution haxx as root on iOS 14 - iOS 14.8.1.

webkit; but pwned

Proof-of-concept IPA for CVE-2021-30955, targeting iOS 15.0-15.2b1, demonstrating a local privilege escalation vulnerability.

Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessary resources for APT repositories.