MobileHackingLab — Runtime Toad Writeup
Exploiting CVE-2025-59489 in Unity's runtime — local and remote RCE via -xrsdk-pre-init-library intent extras.
Exploiting CVE-2025-59489 in Unity's runtime — local and remote RCE via -xrsdk-pre-init-library intent extras.
Chaining path traversal in getLastPathSegment() with unverified native library loading for RCE on MobileHackingLab's Document Viewer.
OS command injection via an unsanitized path string extra in DatabaseViewerActivity.java allows arbitrary command execution when root explorer mode is enabled.
Theft of arbitrary files via execution of attacker-controlled bash scripts through the exported BashAssociation activity.
Part 3: arbitrary code execution via third-party package context loading; vulnerabilities 16-18 listed as stubs.