Stars
smalidea is a smali language plugin for IntelliJ IDEA
To take screenshots easily with Android 5.0 API.{优雅地实现屏幕截图,用android 5.0之后的录屏API实现}
Burp Plugin to decrypt AES encrypted traffic on the fly
Hardware-based attestation / intrusion detection app for Android devices. It provides both local verification with another Android device via QR codes and optional scheduled server-based verificati…
Droidefense: Advance Android Malware Analysis Framework
A collection of reverse engineering challenges for learning about the Android operating system and mobile security.
Joint Advanced Defect assEsment for android applications
Exploit for CVE-2022-20452, privilege escalation on Android from installed app to system app (or another app) via LazyValue using Parcel after recycle()
Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite
Multiple samples showing the best practices in input on Android.
LibScout: Third-party library detector for Java/Android apps
Inject frida agents on local processes through an Android app
Android app analysis and feature extraction library
Root Exploit for DJI Drones and Controllers (up to and including v01.04.0200)
Exploit for Android Zip bugs: 8219321, 9695860, and 9950697
Writeup and exploit for installed app to system privilege escalation on Android 12 Beta through CVE-2021-0928, a `writeToParcel`/`createFromParcel` serialization mismatch in `OutputConfiguration`
Created by High-Tech Bridge, the Purposefully Insecure and Vulnerable Android Application (PIVAA) replaces outdated DIVA for benchmark of mobile vulnerability scanners.
Obtain basic information out of an Android APK file.
A portable utility to locate android binder service
Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation
Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted ApplicationInfo to LoadedApk
CVE-2023-20963 PoC (Android WorkSource parcel/unparcel logic mismatch)