
Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.
Was doing a ton of reading over at https://github.com/Serotav/Writeups.
Decided to combine 85046 with 87491 and bake in some WASM at the same time.
Went and re-did a stage1.js for an eventual ubuntu LPE I'm cooking.
The basics:
sort().Float64Array to read and write the V8 cage.Run ./run.py /path/to/chrome. It serves run.html, makes up to five fresh-profile attempts, and exits as soon as it captures PWNED 2026 from the renderer. Each attempt is limited to 20 seconds.
To go any further you'd have to have an local priv esc of sorts.