Tool to patch the ASLR slide generation in the kernel to disable user-land ASLR on 32-bit iOS
☆32Dec 6, 2020Updated 5 years ago
Alternatives and similar repositories for aslr-kernel-patch
Users that are interested in aslr-kernel-patch are comparing it to the libraries listed below
Sorting:
- Writes to nand_llb and triggers the Image3 SHSH overlap bug☆14Dec 2, 2023Updated 2 years ago
- Binary Ninja loader for A12 SEP firmware☆29Feb 4, 2021Updated 5 years ago
- some research results of sep☆20Apr 9, 2021Updated 4 years ago
- iBoot/SecureROM Loader☆35Feb 24, 2023Updated 3 years ago
- CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same networ…☆74Sep 23, 2020Updated 5 years ago
- Plugin for loading MachO kernelcache and dSYM files to Binary Ninja☆40Mar 23, 2025Updated 11 months ago
- crappy "debugger"-like memory reader, to inspect 32bit ios kernel after it paniced☆16Jan 12, 2019Updated 7 years ago
- My collection of PoCs☆26Nov 9, 2023Updated 2 years ago
- ☆15Oct 27, 2022Updated 3 years ago
- Proof-of-concept and write-up for the CVE-2022-32832 vulnerability patched in iOS 15.6☆96Jul 21, 2022Updated 3 years ago
- ☆26May 19, 2022Updated 3 years ago
- Binary View plugin for reverse engineering iBoot like binaries with Binary Ninja☆55Jan 25, 2024Updated 2 years ago
- iBoot-1145.3 Image3/heap stack RE (+unholy tools)☆83Feb 10, 2024Updated 2 years ago
- This repository discloses a critical vulnerability in Apple’s A16 Bionic chip, where debug logic is executed on production-fused devices …☆15Sep 7, 2025Updated 6 months ago
- ☆14Mar 27, 2023Updated 2 years ago
- RP2040 based iPhone (lightning) UART cable, that actually works☆20Jul 31, 2025Updated 7 months ago
- ☆11Aug 11, 2012Updated 13 years ago
- A tool to write text to the iOS screen by directly modifying the pixel information in the framebuffer☆91Jun 28, 2020Updated 5 years ago
- Dumped entitlements☆17Nov 28, 2021Updated 4 years ago
- Structures, function definitions, and code reversed from old iBoot☆17Oct 25, 2018Updated 7 years ago
- ☆40Feb 10, 2021Updated 5 years ago
- An IDAPython module for enhancing c++ support on top of ida_kernelcache☆141May 15, 2025Updated 10 months ago
- Patch the iBoot64 with generic patches.☆52Mar 19, 2024Updated 2 years ago
- `ipsw` symbolication signatures☆97Updated this week
- Repository for sharing knowledge about Apple system internals and low-level exploitation☆10Feb 13, 2019Updated 7 years ago
- A custom shellcode hook for checkra1n 0.1337 written in c!☆35Dec 20, 2023Updated 2 years ago
- Hopefully an insightful XPC tracer that helps vulerability research by tracing server and client call stacks☆20Jul 19, 2022Updated 3 years ago
- UPDATED: All the action is at https://github.com/xsscx/srd☆13Jul 12, 2021Updated 4 years ago
- API for beta iOS firmwares using The iPhone Wiki info☆15Dec 18, 2022Updated 3 years ago
- Extract iOS firmware keys using on-device AES engine☆41Jul 6, 2022Updated 3 years ago
- IDA loader for Apple's 64 bits iBoot, SecureROM and AVPBooter☆164Nov 2, 2024Updated last year
- An *OS bootchain patching library.☆15Updated this week
- ☆150Oct 11, 2021Updated 4 years ago
- ANE kernel r/w exploit for iOS 15 and macOS 12☆303Nov 20, 2022Updated 3 years ago
- An IDA Toolkit for analyzing iOS kernelcaches.☆110May 15, 2025Updated 10 months ago
- Dev tools for probing IOKit☆202Sep 23, 2023Updated 2 years ago
- An incomplete project for SEP bypass on downgrades/dual-boots☆19Apr 29, 2022Updated 3 years ago
- Segment-accurate iBoot/SecureROM loader for Binary Ninja & IDA Pro☆48Mar 7, 2026Updated last week
- A lightweight ARM reverse engineering tool.☆24Jun 18, 2024Updated last year