
CVE-2026-65330
Proof-of-concept for a fixed PAC diversifier bypass in the tmpfs setxattr handler on iOS 26.6, demonstrating reachability of the vulnerable signing…

Proof-of-concept for a fixed PAC diversifier bypass in the tmpfs setxattr handler on iOS 26.6, demonstrating reachability of the vulnerable signing…

UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.

A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to…

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger…

iOS 3.0-10.3.4 tfp0 kernel exploit


Looney Tunables Local privilege escalation (CVE-2023-4911) workshop

A jailbreak tool for all arm64 devices on iOS 16.0 to iOS 16.6.1

Untethered + Unsandboxed code execution haxx as root on iOS 14 - iOS 14.8.1.

Fugu15 is a semi-untethered permasigned jailbreak for iOS 15

I do some tweaking for iOS from 16.0 to 16.1.2 based on MacDirtyCow (CVE-2022-46689) exploit.


PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

Abusing CVE-2023-28206 to make something useful

CVE-2022-46689


webkit; but pwned

ANE kernel r/w exploit for iOS 15 and macOS 12