Android application security · Manila, PH · 5+ years

Carlo Jae
Avila

Lead Offensive Security Engineer at Secuna. I break mobile apps for fun (still hunting for the profit part)

Android and iOS internals, malware analysis, forensics. Currently pushing into red teaming, OSINT, and offensive AI security research.

// patterns i've broken

source

            

sink

            
// disclosed · all patched upstream

Security Research CVEs

CVE-2024-44336 MEDIUM
Unvalidated implicit intent result leaks private files to a world-readable cache

AnkiDroid Open Source Team · AnkiDroid v2.17.6 · Feb 2025

NVD ↗
CVE-2024-33469 HIGH
OS command injection through an unsanitized path extra in DatabaseViewerActivity

Team Amaze · Amaze File Manager ≤ 3.8.5 · Feb 2024

NVD ↗
CVE-2023-4876 HIGH NVD ↗
CVE-2023-4435 MEDIUM NVD ↗
CVE-2023-4434 MEDIUM NVD ↗
CVE-2023-5948 MEDIUM
setResult misuse in a third-party welcome screen leaks a non-exported FileProvider

Team Amaze · Amaze File Utilities · WelcomeScreen.kt · Aug 2023

NVD ↗
// credentials

Certifications

mobile-heavy, all hands-on exams

CAAH

Certified Advanced Android Hacker

Advanced Android exploitation and vulnerability research, aimed at competition-grade targets.

verify ↗

OMSE

Offensive Mobile Security Expert

iOS and Android security across userland and kernel, including vulnerability research.

verify ↗

eMAPT

eLearnSecurity Mobile Application Penetration Tester

Android application penetration testing, assessed through a fully practical exam.

eWPTXv2

eLearnSecurity Web Application Penetration Tester eXtreme

Advanced web application exploitation and filter-bypass technique.

// currently

Work

Secuna

Manila, PH · cybersecurity platform

  1. Lead Offensive Security Engineer current Jan 2023 – present
  2. Junior Penetration Tester Jul 2021 – Dec 2022
  3. Penetration Testing Intern May 2021 – Jun 2021

hackstreetboys

Manila, PH · CTF team

  1. Member · CTF player current

Profiles

// development

Projects

pwn_exhibit

Archive of CTF writeups and exploit dev notes — binary exploitation, Android reverse engineering, and malware analysis.

Python github ↗