-
JD.com (@jd-opensource)
- Tianjin, China
-
06:59
(UTC +08:00) - https://wrlus.com/me
- @wrlu_xiaolu
Highlights
Starred repositories
LSPass: Bypass restrictions on non-SDK interfaces
Exploit for CVE-2022-20452, privilege escalation on Android from installed app to system app (or another app) via LazyValue using Parcel after recycle()
PoC and writeup for bypassing the initial patch of CVE-2024-0044, Android run-as any app vulnerability allowing privilege escalation from adb to installed app
A portable utility to locate android binder service
Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted ApplicationInfo to LoadedApk
Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code execution from normal installed app
Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used
icespite / FridaHooker
Forked from wrlu/FridaHookerAndroid Frida GUI Manager; Android 图形化Frida管理器