
root@mhfh:~# ./db --stats → ios=11 android=11 critical=11
Mobile Exploit Database
A curated archive of iOS and Android vulnerabilities, CVE metadata, affected versions, proof-of-concept code and downloadable artefacts. Search, filter, and pivot into the full write-up for any entry.
root@mhfh:~#grep -r 'CVE' /var/db/exploits/
exploit-db.sh --query
$ platform:
$ severity:
| CVE | Title | |
|---|---|---|
| CVE-2026-43722 | Kernel sensitive-state information disclosure | cat → |
| CVE-2026-0059 | Android System remote code execution | cat → |
| CVE-2026-0114 | Pixel modem remote code execution | cat → |
| CVE-2026-0006 | Android System remote code execution | cat → |
| CVE-2025-31200 | CoreAudio crafted-media code execution | cat → |
| CVE-2025-31201 | RPAC Pointer Authentication bypass | cat → |
| CVE-2025-14174 | WebKit memory corruption in targeted attacks | cat → |
| CVE-2026-0073 | adbd wireless debugging remote shell | cat → |
| CVE-2026-21385 | Graphics component buffer over-read | cat → |
| CVE-2026-0032 | mem_protect.c out-of-bounds write | cat → |
| CVE-2026-20700 | Memory corruption arbitrary code execution | cat → |
| CVE-2026-20640 | iPhone Mirroring UI state disclosure | cat → |
| CVE-2025-43529 | WebKit Use-After-Free arbitrary code | cat → |
| CVE-2025-48543 | Chrome sandbox escape use-after-free | cat → |
| CVE-2024-23222 | WebKit RCE via type confusion | cat → |
| CVE-2024-44308 | JavaScriptCore UXSS chain | cat → |
| CVE-2023-41064 | BLASTPASS ImageIO 0-click | cat → |
| CVE-2022-32893 | WebKit OOB write → kernel LPE | cat → |
| CVE-2024-32896 | Pixel firmware privilege escalation | cat → |
| CVE-2024-43093 | Framework path traversal sandbox escape | cat → |
| CVE-2023-21492 | Samsung kernel pointer leak | cat → |
| CVE-2023-20963 | WorkSource parcel mismatch (in-the-wild) | cat → |
22 record(s)
root@mhfh:~#secure contact form
secure_channel.enc
$ Open a secure channel via Session. Pre-engagement NDA available on request.
email: info@mobilehackerforhire.com
session: