2 hours ago
Looking for serious buyers only. No time wasters.
What you get:
• Remote code execution in Chrome / WebView
• Confirmed on Android 14 - 16 (Pixel, Samsung, Xiaomi tested)
• Full chain: renderer RCE -> sandbox escape -> system_server pivot
• Pure JavaScript + native shellcode, no APK required
• Works via drive-by (malicious page/ad) or via WebView in third-party apps
• No user interaction beyond loading the page
• In-memory only, no persistent implant unless you add one
• Includes loader, stage-0 JS, stage-1 shellcode, and basic C2 stub
Tested successfully against:
- Pixel 9/9 Pro (Android 15)
- Samsung Galaxy S24 (Android 16, OneUI 8)
- Xiaomi 14 (Android 14, HyperOS)
Proof of concept video available after serious inquiry (screen recording of Galaxy S24, full chain in <4s).
No source for the PAC/SELinux bypass stage (binary only)
BreachForums escrow is accepted.
Price: $10k
Telegram: @xynapsee
What you get:
• Remote code execution in Chrome / WebView
• Confirmed on Android 14 - 16 (Pixel, Samsung, Xiaomi tested)
• Full chain: renderer RCE -> sandbox escape -> system_server pivot
• Pure JavaScript + native shellcode, no APK required
• Works via drive-by (malicious page/ad) or via WebView in third-party apps
• No user interaction beyond loading the page
• In-memory only, no persistent implant unless you add one
• Includes loader, stage-0 JS, stage-1 shellcode, and basic C2 stub
Tested successfully against:
- Pixel 9/9 Pro (Android 15)
- Samsung Galaxy S24 (Android 16, OneUI 8)
- Xiaomi 14 (Android 14, HyperOS)
Proof of concept video available after serious inquiry (screen recording of Galaxy S24, full chain in <4s).
No source for the PAC/SELinux bypass stage (binary only)
BreachForums escrow is accepted.
Price: $10k
Telegram: @xynapsee
