michalbednarski / TheLastBundleMismatch
Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation
☆86Updated last year
Alternatives and similar repositories for TheLastBundleMismatch:
Users that are interested in TheLastBundleMismatch are comparing it to the libraries listed below
- ☆73Updated 3 years ago
- Writeup and exploit for installed app to system privilege escalation on Android 12 Beta through CVE-2021-0928, a `writeToParcel`/`createF…☆115Updated 3 years ago
- PoC of CVE-2022-20474☆13Updated last month
- PoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta☆27Updated 2 years ago
- Android Root Zap Framework, Lazy and Powerful :)☆51Updated 2 years ago
- A black-box fuzzer to detect custom permission related privilege escalation vulnerabilities in Android.☆32Updated 3 years ago
- ☆12Updated 2 years ago
- blabla☆49Updated 4 years ago
- CVE-2023-20963 PoC (Android WorkSource parcel/unparcel logic mismatch)☆57Updated 10 months ago
- Files related to the Pwn2Own Toronto 2023 exploit against the Xiaomi 13 Pro.☆23Updated 5 months ago
- ☆13Updated 3 years ago
- btrace:binder_transaction+eBPF+Golang实现通用的Android APP动态行为追踪工具☆162Updated 9 months ago
- 主要记入自己复现过的android cve☆46Updated 3 years ago
- 010Editor template for .abc (Open/HarmonyOS Ark Bytecode) files☆40Updated 5 months ago
- android app native so fuzz. efficiently run in a real machine with frida environment. See Background: https://idhyt.blogspot.com/2020/02/…☆41Updated last year
- Open/HarmonyOS abc file parser and decompiler☆78Updated 5 months ago
- ☆116Updated last year
- you can use frida in jeb !☆46Updated 2 years ago
- CVE-2024-31317☆25Updated 3 months ago
- The Frida based fuzzer all in one☆30Updated 4 years ago
- Code Scanner For Android Privacy☆38Updated last year
- PendingIntent exploit☆11Updated last year
- A portable utility to locate android binder service☆92Updated 5 years ago
- study launch anywhere and bundle mismatch bug☆13Updated last year
- Use angr to deflat the flat control flow.☆23Updated 5 years ago
- PoC and writeup for bypassing the initial patch of CVE-2024-0044, Android run-as any app vulnerability allowing privilege escalation from…☆143Updated 5 months ago
- ☆59Updated 8 months ago
- Hardware Assisted Unpacking of Android Apps☆55Updated 3 years ago
- Android-DirtyStream Vuln Demo☆27Updated 10 months ago
- a demo poc for CVE-2024-0015☆14Updated 7 months ago