Bugbane is currently experimental software distributed as a beta. It has not yet received an independent security audit. Before using it, please read and understand the limitations and precautions below.
Using Bugbane is not covert: its installation and use can be detectable and knowable — by someone who inspects or controls your device, or by the spyware itself. If you are a victim of stalkerware or spyware and are under physical or serious personal risk, the use of Bugbane is discouraged: a detected scan could alert the abuser and escalate the danger. In those circumstances, contact our technical support helpline from a safe device first.
Bugbane detects spyware using a combination of heuristics and signature matching against public and private Indicators of Compromise (IoCs).
Bugbane pairs with your device over wireless debugging (ADB over Wi-Fi). The app must not be used on public, unencrypted, or untrusted Wi-Fi networks. Only run acquisitions on a network you control and trust — ideally a personal hotspot.
Devices running Android 14 to 16 that are missing the May 2026 security patch are affected by CVE-2026-0073, a wireless-ADB authentication bypass: while Wireless Debugging is enabled, an attacker on the same network can gain access to the device with no user interaction.
Bugbane tries to detect whether your device is patched and warns you if it is not — checking both the system security patch level and Google Play system updates, since the fix may already be in effect through the latter even if the security patch level looks too old. If the warning is displayed:
Bugbane saves acquisitions and analysis results on the device itself. This data is encrypted, but non-consensual forensic tools such as Cellebrite or Oxygen Forensic might still manage to extract it. If you think you are at risk of such practices, it is recommended to set the additional password — choosing a high-entropy one — when prompted at the end of your first acquisition, or later from the app settings. If the risk is really high, consider using forensic tools running on another device instead.
If you suspect you are being targeted by spyware or digital surveillance, do not rely solely on this app — reach out to our technical support helpline.