xnu_gym is a pongoOS module that patches XNU to reintroduce previously known and patched vulnerabilities. This is an easy way to practice kernel exploitation and jailbreak development!
☆59Jun 17, 2021Updated 5 years ago
Alternatives and similar repositories for xnu_gym
Users that are interested in xnu_gym are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- iBoot/SecureROM Loader☆35Feb 24, 2023Updated 3 years ago
- Binary Ninja loader for A12 SEP firmware☆30Feb 4, 2021Updated 5 years ago
- Writes to nand_llb and triggers the Image3 SHSH overlap bug☆14Dec 2, 2023Updated 2 years ago
- Small binja plugin to import header file to types☆17Nov 11, 2022Updated 3 years ago
- WebKit/JSC CodeQL Databases☆17Dec 15, 2025Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Binary View plugin for reverse engineering iBoot like binaries with Binary Ninja☆56Jan 25, 2024Updated 2 years ago
- some research results of sep☆20Apr 9, 2021Updated 5 years ago
- UPDATED: All the action is at https://github.com/xsscx/srd☆12Jul 12, 2021Updated 5 years ago
- Binary Ninja loader for 64 bits Apple SEPROMs☆59Sep 7, 2025Updated 10 months ago
- Find some iBoot functions in an iBoot64.☆40Feb 10, 2021Updated 5 years ago
- A set of tools for fuzzing SecureROM. Managed to find and trigger checkm8.☆168Sep 18, 2021Updated 4 years ago
- A plugin for Binary Ninja to query the Symgrate2 database.☆14Sep 11, 2021Updated 4 years ago
- Demo exploit code for CVE-2020-27904, a tfp0 bug.☆68Apr 29, 2021Updated 5 years ago
- An Open-Source Work-In-Progress iOS 6 Jailbreak Using a Custom Ramdisk☆11May 13, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same networ…☆73Sep 23, 2020Updated 5 years ago
- Patch the iBoot64 with generic patches.☆54Mar 19, 2024Updated 2 years ago
- Experimentation environment for checkm8-vulnerable devices☆57Dec 30, 2023Updated 2 years ago
- a7 sep bug☆54Sep 26, 2023Updated 2 years ago
- A tool to pull C++ object names from kernel memory☆16Aug 13, 2021Updated 4 years ago
- for 32-bit iboot bug on ios 7☆17Mar 11, 2020Updated 6 years ago
- Fork of PongoOS which can be run in QEMU☆70Jun 7, 2021Updated 5 years ago
- iOS system call/Mach trap interception for checkra1n'able devices☆163Aug 10, 2021Updated 4 years ago
- iOS 5.x iBoot fun for the whole family!☆42Apr 23, 2020Updated 6 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Easily patch ASR on 64-bit devices.☆22Jun 24, 2021Updated 5 years ago
- ☆16Jul 30, 2020Updated 5 years ago
- Python tools of varying usefulness related to iOS jailbreaking.☆31Jan 6, 2022Updated 4 years ago
- Boot arbitrary iBoot via ipwndfu's custom protocol on 32-bit platforms (and more)☆71Dec 21, 2025Updated 7 months ago
- Binja Arm64 Disassembler☆106Feb 10, 2026Updated 5 months ago
- A quick way to sign iBSS - iBEC and upload it to device☆18Feb 7, 2020Updated 6 years ago
- An *OS bootchain patching library.☆16Updated this week
- ☆42Aug 5, 2021Updated 4 years ago
- ☆13Dec 5, 2020Updated 5 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- iOS Userland Forensic Dumping Framework for iOS 7/8☆21Apr 4, 2026Updated 3 months ago
- iOS bootchain patchers in Python☆14Jan 23, 2024Updated 2 years ago
- Tool to patch the ASLR slide generation in the kernel to disable user-land ASLR on 32-bit iOS☆32Dec 6, 2020Updated 5 years ago
- an iOS kernel function hooking framework for checkra1n'able devices☆596Oct 6, 2021Updated 4 years ago
- 64-bit iOS boot image patcher written in C☆148Sep 18, 2022Updated 3 years ago
- Dev tools for probing IOKit☆204Sep 23, 2023Updated 2 years ago
- IDA loader for Apple's 64 bits iBoot, SecureROM and AVPBooter☆171Nov 2, 2024Updated last year