Supersonic/TLPE
CVE-2026-49881, using insecure context creation in Android 17's Telecom service to execute arbitrary code as UID 1000 system_server from an unprivileged app
About the project
PoC and writeup for CVE-2026-49881, a logic flaw in Android 17's Telecom InCallController that lets an unprivileged app execute code as UID 1000 system_server with no user interaction.
Useful for
- Reproduce the vulnerability on a test device and check logcat output
- Study the InCallController call chain to audit Android Telecom
- Verify whether the flaw is fixed after installing the security patch
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 2 stars today.
- The repository is 4 days old and already has 87 stars.
- Top new repositories this week: #173.
- Recent forks include notable developers: @CrackerCat (1,065 followers).
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 87
- Stars in a day
- 2
- Forks
- 9
- Issues and pull requests
- 0
- Watchers
- 0
- Language
- Kotlin
- Latest release
- v0 · September 9, 2026
- Created
- September 9, 2026
- Last push
- September 9, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 13, 2026Top new repositories this week: #157
Similar projects
-
7.0
SnailSploit/Claude-Red
A curated library of drop-in SKILL.md files for the Claude Skills system that primes Claude with offensive security methodology, from SQL injection to EDR evasion and exploit development.
-
6.2
vxcontrol/pentagi
Autonomous multi-agent system in Go for automated penetration testing: AI agents plan and execute steps in an isolated Docker sandbox with 20+ tools (nmap, metasploit, sqlmap).
-
5.0
hezhanleiok/freesub
Automatically tests and publishes subscription pools of free proxy nodes (VLESS, VMess, Trojan, Shadowsocks, Hysteria2, TUIC, AnyTLS), filtering out dead and hijacked nodes via real HTTPS handshakes and TLS validation.
-
4.9
tsymbaluyk/maskgate
PII masking service that detects passports, tax IDs, SNILS, bank cards, phones, medical data and secrets in text and files and masks them before they reach ChatGPT, Claude, Gemini. Source code is proprietary; this repo…
-
4.3
zhihui-hu/one-ip
Web tool for IP lookups: identifies datacenter, VPN, Tor and proxy usage, rates reputation from 0 to 100, shows ASN, WHOIS, DNS, CDN, geolocation and checks AI service reachability.
-
4.2
realchendahuang/feedsieve
A Chrome extension that flags spam accounts on X (Twitter) with a yellow border and lets you block them manually or in bulk via the native API, synced across all devices.