Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-9973-exploit — استغلال إثبات المفهوم لثغرة CVE-2026-9973، وهي ثغرة في آلية إزالة التحميل (Load Elimination) بمحرك V8 Turboshaft تتيح الهروب من بيئة الحماية المعزولة (sandbox escape) في Chromium. يوضح إفساد الذاكرة عبر JavaScript مُصمَّمة بعناية. | Kitploit
أدوات/GitHubGitHub/jaf0rk/cve-2026-9973-exploit
تحليل الثغرات الأمنيةالاستغلالشيل كوداستغلال تطبيقات الويبتطوير الحمولاتاستغلال الملفات الثنائية
GitHubjaf0rk/cve-2026-9973-exploit

CVE-2026-9973-exploit

استغلال إثبات المفهوم لثغرة CVE-2026-9973، وهي ثغرة في آلية إزالة التحميل (Load Elimination) بمحرك V8 Turboshaft تتيح الهروب من بيئة الحماية المعزولة (sandbox escape) في Chromium. يوضح إفساد الذاكرة عبر JavaScript مُصمَّمة بعناية.

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودع
62منذ شهر واحدلم تتم المراجعة بعد

CVE-2026-9973

إصلاح خلل

https://chromium-review.googlesource.com/c/v8/v8/+/7822799

root@kitploit:~
[wasm][turboshaft] Fix Phi handling in Load Elimination some more

Multiple Phis can depend on each other, so we have to clear all their
replacements up front.

Fixed: 509268941
Change-Id: I7899b28e89ed7b470bd869fb52f7443589305171
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7822799
Reviewed-by: Darius Mercadier <[email protected]>
Auto-Submit: Jakob Kummerow <[email protected]>
Commit-Queue: Jakob Kummerow <[email protected]>
Cr-Commit-Position: refs/heads/main@{#107278}

البيئة

نظام التشغيل: Ubuntu 24.04 noble x64

إصدار v8: 14.8.178.21

root@kitploit:~
commit e38030f4228c8d1405fe105fc5feaa5173559e25 (HEAD -> 14.8.178.21, tag: 14.8.178.21-pgo, tag: 14.8.178.21)
Author: V8 Autoroll <v8-ci-autoroll-builder@chops-service-accounts.iam.gserviceaccount.com>
Date:   Wed May 6 13:34:13 2026 -0700

    Version 14.8.178.21
    
    Version incremented at https://cr-buildbucket.appspot.com/build/8682521216270456209
    
    Change-Id: I16a5eb6f12bf2c64d5a7eac752a09128e4eac6fb
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7822581
    Bot-Commit: v8-ci-autoroll-builder@chops-service-accounts.iam.gserviceaccount.com <v8-ci-autoroll-builder@chops-service-accounts.iam.gserviceaccount.com>
    Cr-Commit-Position: refs/branch-heads/14.8@{#43}
    Cr-Branched-From: f9659283a5f8d42b3c09228cf5df606fcaf47a3d-refs/heads/14.8.178@{#1}
    Cr-Branched-From: 141232520dc4910401240c531db3af36910a0fd1-refs/heads/main@{#106240}

وسائط البناء:

root@kitploit:~
# Set build arguments here. See `gn help buildargs`.
is_debug = false
dcheck_always_on = false
v8_symbol_level = 2
v8_enable_object_print = true
v8_enable_sandbox = true
target_os = "linux"
target_cpu = "x64"

الاستخدام

شغّل الـ ExP باستخدام:

root@kitploit:~
d8 --allow-natives-syntax exp.js

ملاحظات إضافية

لا يزال البحث في جزء الهروب من صندوق حماية V8 (sandbox escape) قيد التقدم.

النتيجة

elements == object address

root@kitploit:~
=========================Address=========================
fake object address: 1060f5d
=======================DebugPrint========================
DebugPrint: 0x16201060f5d: [JSArray]
 - map: 0x01620100d0d9 <Map[16](https://github.com/jaf0rk/cve-2026-9973-exploit/blob/HEAD/PACKED_DOUBLE_ELEMENTS)> [FastProperties]
 - prototype: 0x01620100ca3d <JSArray[0]>
 - elements: 0x016201060f5d <JSArray[2]> [PACKED_DOUBLE_ELEMENTS]
 - length: 2
 - properties: 0x0162000007e5 <FixedArray[0]>
 - All own properties (excluding elements): {
    0x16200000e19: [String] in ReadOnlySpace: #length: 0x0162001a6add <AccessorInfo name= 0x016200000e19 <String[6]: #length>, data= 0x016200000011 <undefined>> (const accessor descriptor, attrs: [W__])
 }
 // This is object address
 - elements: 0x016201060f5d <JSArray[2]> {   Unexpected elements backing store

 }
0x1620100d0d9: [Map] in OldSpace
 - map: 0x016201004939 <MetaMap (0x016201004989 <NativeContext[307]>)>
 - type: JS_ARRAY_TYPE
 - instance size: 16
 - inobject properties: 0
 - unused property fields: 0
 - elements kind: PACKED_DOUBLE_ELEMENTS
 - enum length: invalid
 - back pointer: 0x01620100d095 <Map[16](https://github.com/jaf0rk/cve-2026-9973-exploit/blob/HEAD/HOLEY_SMI_ELEMENTS)>
 - prototype_validity_cell: 0x016200000af1 <Cell value= [cleared]>
 - instance descriptors #1: 0x01620100d059 <DescriptorArray[1]>
 - transitions #1: 0x01620100d101 <TransitionArray[5]>
   Transitions #1:
     0x016200000eb5 <Symbol: (elements_transition_symbol)>: (transition to HOLEY_DOUBLE_ELEMENTS) -> 0x01620100d11d <Map[16](https://github.com/jaf0rk/cve-2026-9973-exploit/blob/HEAD/HOLEY_DOUBLE_ELEMENTS)>
 - prototype: 0x01620100ca3d <JSArray[0]>
 - constructor: 0x01620100c965 <JSFunction Array (sfi = 0x162001ac43d)>
 - dependent code: 0x0162000007f5 <Other heap object (WEAK_ARRAY_LIST_TYPE)>
 - construction counter: 0

تنزيل الأداة