Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/jaf0rk/cve-2026-9973-exploit
Vulnerability AnalysisExploitationShellcodeWeb Application ExploitationPayload DevelopmentBinary ExploitationRepository Deleted
GitHubjaf0rk/cve-2026-9973-exploit

CVE-2026-9973-exploit

Proof-of-concept exploit for CVE-2026-9973, a V8 Turboshaft Load Elimination vulnerability enabling sandbox escape in Chromium. Demonstrates memory corruption via crafted JavaScript.

The upstream repository was not found during the latest Kitploit update check. This listing remains available for reference, but it has been removed from search results.
6231 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-9973

Bug fix

https://chromium-review.googlesource.com/c/v8/v8/+/7822799

root@kitploit:~
[wasm][turboshaft] Fix Phi handling in Load Elimination some more

Multiple Phis can depend on each other, so we have to clear all their
replacements up front.

Fixed: 509268941
Change-Id: I7899b28e89ed7b470bd869fb52f7443589305171
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7822799
Reviewed-by: Darius Mercadier <[email protected]>
Auto-Submit: Jakob Kummerow <[email protected]>
Commit-Queue: Jakob Kummerow <[email protected]>
Cr-Commit-Position: refs/heads/main@{#107278}

Environment

OS: Ubuntu 24.04 noble x64

v8 version: 14.8.178.21

root@kitploit:~
commit e38030f4228c8d1405fe105fc5feaa5173559e25 (HEAD -> 14.8.178.21, tag: 14.8.178.21-pgo, tag: 14.8.178.21)
Author: V8 Autoroll <v8-ci-autoroll-builder@chops-service-accounts.iam.gserviceaccount.com>
Date:   Wed May 6 13:34:13 2026 -0700

    Version 14.8.178.21
    
    Version incremented at https://cr-buildbucket.appspot.com/build/8682521216270456209
    
    Change-Id: I16a5eb6f12bf2c64d5a7eac752a09128e4eac6fb
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7822581
    Bot-Commit: v8-ci-autoroll-builder@chops-service-accounts.iam.gserviceaccount.com <v8-ci-autoroll-builder@chops-service-accounts.iam.gserviceaccount.com>
    Cr-Commit-Position: refs/branch-heads/14.8@{#43}
    Cr-Branched-From: f9659283a5f8d42b3c09228cf5df606fcaf47a3d-refs/heads/14.8.178@{#1}
    Cr-Branched-From: 141232520dc4910401240c531db3af36910a0fd1-refs/heads/main@{#106240}

build args:

root@kitploit:~
# Set build arguments here. See `gn help buildargs`.
is_debug = false
dcheck_always_on = false
v8_symbol_level = 2
v8_enable_object_print = true
v8_enable_sandbox = true
target_os = "linux"
target_cpu = "x64"

Usage

Run the ExP with:

root@kitploit:~
d8 --allow-natives-syntax exp.js

Additional Notes

Research on the V8 sandbox escape portion is still in progress.

Result

elements == object address

root@kitploit:~
=========================Address=========================
fake object address: 1060f5d
=======================DebugPrint========================
DebugPrint: 0x16201060f5d: [JSArray]
 - map: 0x01620100d0d9 <Map[16](https://github.com/jaf0rk/cve-2026-9973-exploit/blob/main/PACKED_DOUBLE_ELEMENTS)> [FastProperties]
 - prototype: 0x01620100ca3d <JSArray[0]>
 - elements: 0x016201060f5d <JSArray[2]> [PACKED_DOUBLE_ELEMENTS]
 - length: 2
 - properties: 0x0162000007e5 <FixedArray[0]>
 - All own properties (excluding elements): {
    0x16200000e19: [String] in ReadOnlySpace: #length: 0x0162001a6add <AccessorInfo name= 0x016200000e19 <String[6]: #length>, data= 0x016200000011 <undefined>> (const accessor descriptor, attrs: [W__])
 }
 // This is object address
 - elements: 0x016201060f5d <JSArray[2]> {   Unexpected elements backing store

 }
0x1620100d0d9: [Map] in OldSpace
 - map: 0x016201004939 <MetaMap (0x016201004989 <NativeContext[307]>)>
 - type: JS_ARRAY_TYPE
 - instance size: 16
 - inobject properties: 0
 - unused property fields: 0
 - elements kind: PACKED_DOUBLE_ELEMENTS
 - enum length: invalid
 - back pointer: 0x01620100d095 <Map[16](https://github.com/jaf0rk/cve-2026-9973-exploit/blob/main/HOLEY_SMI_ELEMENTS)>
 - prototype_validity_cell: 0x016200000af1 <Cell value= [cleared]>
 - instance descriptors #1: 0x01620100d059 <DescriptorArray[1]>
 - transitions #1: 0x01620100d101 <TransitionArray[5]>
   Transitions #1:
     0x016200000eb5 <Symbol: (elements_transition_symbol)>: (transition to HOLEY_DOUBLE_ELEMENTS) -> 0x01620100d11d <Map[16](https://github.com/jaf0rk/cve-2026-9973-exploit/blob/main/HOLEY_DOUBLE_ELEMENTS)>
 - prototype: 0x01620100ca3d <JSArray[0]>
 - constructor: 0x01620100c965 <JSFunction Array (sfi = 0x162001ac43d)>
 - dependent code: 0x0162000007f5 <Other heap object (WEAK_ARRAY_LIST_TYPE)>
 - construction counter: 0