Dimitri Os
2,239 posts
Senior Security Researcher @Microsoft | Android Security Obsessed | Pwn2Own 2025 | Side projects → github.com/Ch0pin
- Bypassing root detection , certificate pinning using github.com/Ch0pin/medusa anti_debug and unpinner modules @Einstais @mobilesecurity_
00:00 - There are countless tutorials, blog posts, and workshops on how to exploit a vulnerability. What’s missing is the thought process — how you approach a target, form hypotheses, and ultimately discover a bug. That mindset can’t be fully taught; you have to develop it yourself ;)
- Heap exploitation techniques for humans: House of Spirit: valsamaras.medium.com/the-toddlers-i… House of Lore: valsamaras.medium.com/the-toddlers-i… FastBin dup to stack: valsamaras.medium.com/the-toddlers-i… FastBin Dup Consolidate: valsamaras.medium.com/the-toddlers-i… Unsafe Unlink: valsamaras.medium.com/the-toddlers-i…
- !Brilliant! post by Quarkslab on fuzzing Android Native libraries using Afl++'s Frida mode: blog.quarkslab.com/android-greybo…
- ARM 64 Assembly Series — Data Processing (Part 2)
- JSON CSRF with method override
- Its hard to keep track with changes in Android, this helps a lot:
- Gave up my weekends to prep for Pwn2Own — totally worth it! Together with the legend @Yogehi, we won the Remote/Mobile category, achieving code execution via a chain of 5 vulnerabilities. Grateful we found it before the bad guys did 😉It's confirmed! Ken Gannon / 伊藤 剣 (@Yogehi) of Mobile Hacking Lab, and Dimitrios Valsamaras (@Ch0pin) of Summoning Team (@SummoningTeam) used five different bugs to exploit the #Samsung Galaxy S25. They earn $50,000 and 5 Master of Pwn points. #Pwn2Own
- The level of ignorance in mobile pentesting is reaching alarming levels.
- Interested about: ARM 64 Assembly, Linux Binary Exploitation, Heap exploitation, Android Security ?? check this out:
- ❌ Wrong: “Victim must install a malicious app” ✅ Right: “Any 3rd-party app can exploit it” Legit apps (e.g. Chrome) can be abused as gadgets, turning complex bugs into 1-click exploits. No excuse to leave it unfixed.
- Road to fuzzing android applications Creating JVM instances: medium.com/@valsamaras/cr…
- (CVE-2022-47757) Two clicks to RCE for more than 1B users: cve.mitre.org/cgi-bin/cvenam…








