Experimental Status and Risks.

Bugbane is currently experimental software distributed as a beta. It has not yet received an independent security audit. Before using it, please read and understand the limitations and precautions below.

If you are at physical or serious personal risk #

Using Bugbane is not covert: its installation and use can be detectable and knowable — by someone who inspects or controls your device, or by the spyware itself. If you are a victim of stalkerware or spyware and are under physical or serious personal risk, the use of Bugbane is discouraged: a detected scan could alert the abuser and escalate the danger. In those circumstances, contact our technical support helpline from a safe device first.

What a scan can — and cannot — tell you #

Bugbane detects spyware using a combination of heuristics and signature matching against public and private Indicators of Compromise (IoCs).

  • No findings does not mean your phone is secure. A clean scan only means nothing matched the indicators and heuristics available at the time of the scan.
  • Bugbane is unlikely to catch previously unseen or unknown spyware, in particular state-sponsored and highly sophisticated tooling that has not yet been publicly documented.
  • The data acquired during a scan is still valuable: it can support forensic analysis and retrospective assessments, for example re-scanning an old acquisition once new indicators are published, or sharing an encrypted report with experts for in-depth investigation.

Network precautions #

Bugbane pairs with your device over wireless debugging (ADB over Wi-Fi). The app must not be used on public, unencrypted, or untrusted Wi-Fi networks. Only run acquisitions on a network you control and trust — ideally a personal hotspot.

Special warning: CVE-2026-0073 (Android 14–16) #

Devices running Android 14 to 16 that are missing the May 2026 security patch are affected by CVE-2026-0073, a wireless-ADB authentication bypass: while Wireless Debugging is enabled, an attacker on the same network can gain access to the device with no user interaction.

Bugbane tries to detect whether your device is patched and warns you if it is not — checking both the system security patch level and Google Play system updates, since the fix may already be in effect through the latter even if the security patch level looks too old. If the warning is displayed:

  • Install system updates first, if you can.
  • If you cannot update, run the scan only on a personal hotspot created by another phone or computer you trust — never on shared or public Wi-Fi.
  • Never keep Wireless Debugging enabled after the scan: turn it off as soon as the acquisition is done. The app will also remind you with a notification.

Data stored on the device #

Bugbane saves acquisitions and analysis results on the device itself. This data is encrypted, but non-consensual forensic tools such as Cellebrite or Oxygen Forensic might still manage to extract it. If you think you are at risk of such practices, it is recommended to set the additional password — choosing a high-entropy one — when prompted at the end of your first acquisition, or later from the app settings. If the risk is really high, consider using forensic tools running on another device instead.

If you believe you are being targeted #

If you suspect you are being targeted by spyware or digital surveillance, do not rely solely on this app — reach out to our technical support helpline.