// about

/path/to/pwn_

Security research notes by Carlo Jae Avila — CVE deep-dives and exploit write-ups from breaking mobile apps and their internals. Everything here is hands-on: real source at the vulnerable commit, full proof-of-concepts, actual output.

// latest

Most recent

mobile 8 min
MobileHackingLab — Runtime Toad Writeup Exploiting CVE-2025-59489 in Unity's runtime — local and remote RCE via -xrsdk-pre-init-library intent extras. read →
// explore

Both archives