Android401 A 0-click Exploit Chain for the Pixel 9, Part 3: Where Do We Go From Here?
Natalie Silvanovich’s Part 3: the Pixel 9 0-click was person-weeks, not a miracle. Rare codecs on transcription, missing seccomp, kASLR dead since…
Android401 Natalie Silvanovich’s Part 3: the Pixel 9 0-click was person-weeks, not a miracle. Rare codecs on transcription, missing seccomp, kASLR dead since…
Android490 Seth Jenkins’s Part 2: from mediacodec to kernel R/W on Pixel 9 via CVE-2025-36934 in /dev/bigwave. A 16-second ioctl timeout UAF becomes…
Android522 Project Zero’s Natalie Silvanovich turns CVE-2025-54957 in the Dolby Unified Decoder into mediacodec code execution on a Pixel 9 with no tap:…
Android591 Quarkslab shows Android hardware attestation end to end, then a Frida relay: a clean phone signs the backend nonce, the rooted analysis…
Android535 A critical SQL injection vulnerability in Android 17's ContactsProvider allows apps using the system contact picker to exfiltrate all contacts on a…
Exploit Development367 CVE-2024-1065 is a physical-page use-after-free in the ARM Mali GPU kernel driver. Because the freed page lands in MIGRATE_MOVABLE, Dirty Pagetable and…
Android376 An original English rewrite of Alexandre Adamski’s 2021 Impalabs deep dive into Samsung’s Real-time Kernel Protection (RKP). The post walks through three…
Application Security426 A practical, security-engineering view of the essential iOS hardening steps every iPhone user — and especially high-risk targets — should apply: Lockdown…