-
ResourcePoison Public
Forked from michalbednarski/ResourcePoisonWriteup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted ApplicationInfo to LoadedApk
Java UpdatedOct 8, 2025 -
ThisSeemsWrong Public
Forked from michalbednarski/ThisSeemsWrongWriteup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used
Java UpdatedOct 8, 2025 -
AbxOverflow Public
Forked from michalbednarski/AbxOverflowWriteup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code execution from normal installed app
Java UpdatedOct 8, 2025 -
LeakValue Public
Forked from michalbednarski/LeakValueExploit for CVE-2022-20452, privilege escalation on Android from installed app to system app (or another app) via LazyValue using Parcel after recycle()
-
OrganizerTransaction Public
Forked from michalbednarski/OrganizerTransactionPoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta
-
ReparcelBug2 Public
Forked from michalbednarski/ReparcelBug2Writeup and exploit for installed app to system privilege escalation on Android 12 Beta through CVE-2021-0928, a `writeToParcel`/`createFromParcel` serialization mismatch in `OutputConfiguration`
-
ovaa Public
Forked from oversecured/ovaaOversecured Vulnerable Android App
-
-
Coeus Public
Forked from wulio/CoeusAndroid apk/sdk Scan包括android apk/sdk 安全审计代码扫描以及国内政策扫描
-
house Public
Forked from nccgroup/houseA runtime mobile application analysis toolkit with a Web GUI, powered by Frida, written in Python.
JavaScript MIT License UpdatedJun 27, 2019 -
Frida-Android-unpack Public
Forked from xiaokanghub/Frida-Android-unpackthis unpack script for Android O and Android P
JavaScript UpdatedJun 4, 2019 -
Street-Party Public
Forked from googleprojectzero/Street-PartyStreet Party is a suite of tools that allows the RTP streams of video conferencing implementations to be viewed and modified.
C++ Apache License 2.0 UpdatedDec 13, 2018 -
-
CVE-2018-9411 Public
Forked from tamirzb/CVE-2018-9411Exploit code for CVE-2018-9411 for MediaCasService
-
Bluedroid Public
Forked from hausferd/BluedroidPoCs of Vulnerabilities on Bluedroid
C UpdatedJun 6, 2018 -
ReparcelBug Public
Forked from michalbednarski/ReparcelBugCVE-2017-0806 PoC (Android GateKeeperResponse writeToParcel/createFromParcel mismatch)
Java UpdatedJun 3, 2018 -
CVE-2017-13253 Public
Forked from tamirzb/CVE-2017-13253PoC code for CVE-2017-13253
-
static-arm-bins Public
Forked from therealsaumil/static-arm-binsStatically compiled ARM binaries for debugging and runtime analysis
Do What The F*ck You Want To Public License UpdatedFeb 27, 2018 -
-
-
android_vuln_poc-exp Public
Forked from jiayy/android_vuln_poc-expThis project contains pocs and exploits for android vulneribilities
-
-
blueborne Public
Forked from ArmisSecurity/blueborneContains PoC scripts demonstrating the BlueBorne vulnerabilities
-
-
-
-
flexidie Public
Forked from Te-k/flexidieSource code and binaries of FlexiSpy from the Flexidie dump
Objective-C UpdatedApr 23, 2017 -
kernel-exploits Public
Forked from xairy/kernel-exploitsA bunch of proof-of-concept exploits for the Linux kernel
C UpdatedFeb 26, 2017 -
VIKIROOT Public
Forked from hyln9/VIKIROOTCVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow
C GNU General Public License v3.0 UpdatedJan 25, 2017 -