ChromSploit Framework v3.0
Overview
ChromSploit Framework is a cutting-edge educational security research tool designed for cybersecurity professionals, researchers, and students. Built with a modular architecture, it provides a comprehensive platform for studying browser vulnerabilities and exploitation techniques in controlled environments.
IMPORTANT: This framework is intended exclusively for educational purposes and authorized security testing. Unauthorized use is strictly prohibited and may violate applicable laws.
Key Highlights
- Intelligent Browser Detection: Automatic browser identification and exploit recommendations
- Analytics Dashboard: Real-time monitoring and performance metrics
- Performance Optimization: Advanced caching system for faster execution
- Enhanced Safety: Multi-level authorization and target validation
- Automated Testing: Browser test automation with Selenium/Playwright
- Multi-Exploit Chains: Automated combination of multiple CVEs
- Advanced Obfuscation: EXTREME-level payload obfuscation with 9+ techniques
- Auto-Ngrok Integration: Automatic tunnel creation for seamless exploitation
- Professional Reporting: Comprehensive PDF/HTML/JSON reports
Features
Core Capabilities
- 9 Advanced CVE Exploits with real functional code
- Browser Detection & Auto-Selection for intelligent targeting
- Monitoring & Analytics Dashboard with real-time metrics
- Caching System for performance optimization
- Enhanced Safety & Authorization with multi-level controls
- Browser Test Automation (Selenium/Playwright)
- Browser Multi-Exploit Chain for automated attacks
- AI-Powered Orchestration for intelligent exploit selection
- Self-Healing Modules for resilient operations
- Enhanced Error Handling with smart recovery
|
Advanced Features
- Extreme Payload Obfuscation (Control Flow, String Encryption, Anti-VM)
- Automatic Ngrok Tunneling (TCP, HTTP, WebSocket)
- Professional Security Reports (PDF, HTML, Markdown, JSON)
- Terminal Recording System with web playback
- Modular Plugin Architecture for extensibility
- Comprehensive Test Framework with validation
- Compatibility Matrix for browser version tracking
- Success Rate Tracking per CVE
- Browser Distribution Analytics
- Historical Data Management
|
Quick Start
Prerequisites
- Python 3.9+ with pip
- Git for repository operations
- Virtual Environment (recommended)
- Administrative privileges (for some features)
Installation
# 1. Clone the repository
git clone https://github.com/Leviticus-Triage/ChromSploit-Framework.git
cd ChromSploit-Framework
# 2. Create virtual environment
python3 -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
# 3. Install dependencies
pip install -r requirements.txt
# 4. Launch ChromSploit
python chromsploit.py
First Run
# Safe mode (recommended for first run)
python chromsploit.py --simulation safe
# With debug output
python chromsploit.py --debug
# Environment check
python chromsploit.py --check
CVE Exploit Arsenal
Click to expand CVE details
Browser Exploits
| CVE ID | Target | Type | Description | Status |
|---|
| CVE-2025-4664 | Chrome | Data Leak | Link header referrer policy bypass | Functional |
| CVE-2025-2783 | Chrome | Sandbox Escape | Mojo IPC handle confusion | Functional |
| CVE-2025-30397 | Edge | Memory Corruption | WebAssembly JIT type confusion | Functional |
| CVE-2025-2857 | Firefox | Sandbox Escape | IPDL privilege escalation | Functional |
| CVE-2025-49741 | Edge | Information Disclosure | Internal request data leakage | Functional |
| CVE-2020-6519 | Chromium | CSP Bypass | Content Security Policy bypass | Functional |
| CVE-2017-5375 | Firefox | RCE | ASM.JS JIT-Spray Remote Code Execution | Functional |
Server-Side Exploits
| CVE ID | Target | Type | Description | Status |
|---|
| CVE-2025-24813 | Apache Tomcat | RCE | Malicious WAR deployment | Functional |
| CVE-2024-32002 | Git | RCE | Symbolic link repository attack | Functional |
New in v3.0: Intelligent Features
Browser Detection & Auto-Selection
Automatically detect browser type and version from User-Agent strings and recommend compatible exploits:
from modules.detection import get_browser_detector
detector = get_browser_detector()
browser_info = detector.detect_browser(user_agent)
recommendations = detector.recommend_exploit(browser_info)
Features:
- Supports Chrome, Edge, Firefox, Brave, Vivaldi, Opera, Safari
- Version parsing and compatibility checking
- Intelligent exploit recommendations based on browser version
- Compatibility matrix for all CVEs
Monitoring & Analytics Dashboard
Real-time tracking and analytics for exploit execution:
- Success Rate Tracking: Per-CVE success rate calculation
- Performance Metrics: Execution time and performance statistics
- Browser Distribution: Analytics on target browser distribution
- Historical Data: Last 1000 exploit attempts tracked
- Report Export: JSON report generation
Access via: Main Menu → Analytics Dashboard
Caching System
Advanced caching for improved performance:
- Payload Caching: Automatic caching of generated payloads
- Obfuscation Caching: Cache obfuscation results
- Browser Detection Caching: 24-hour TTL for detection results
- Persistent Storage: JSON-based persistent cache
- LRU Eviction: Automatic cache management
Enhanced Safety & Authorization
Multi-level safety controls:
- Exploit Authorization: Per-user/exploit authorization system
- Target Validation: Localhost checks and production warnings
- Sandbox Mode: Default safe mode for testing
- Safety Levels: SAFE, RESTRICTED, STANDARD, UNRESTRICTED
- Audit Logging: Comprehensive action tracking
Browser Test Automation
Automated browser testing with Selenium/Playwright:
- Multi-Browser Testing: Test exploits across different browsers
- Automated Validation: Verify exploit execution
- Test Reports: Detailed test results
- Screenshot Support: Visual verification
Browser Multi-Exploit Chain
The flagship feature that automates exploitation of multiple browser CVEs in sequence:
graph LR
A[CVE-2025-4664<br/>Reconnaissance] --> B[CVE-2025-2857<br/>OAuth Theft]
B --> C[CVE-2025-30397<br/>WebAssembly JIT]
C --> D[CVE-2025-2783<br/>Sandbox Escape]
style A fill:#e1f5fe
style B fill:#f3e5f5
style C fill:#fff3e0
style D fill:#ffebee
Enhanced Features
- Extreme Obfuscation: Control flow flattening, string encryption, anti-debugging
- Auto-Ngrok: Automatic tunnel creation for all callbacks
- Parallel Execution: Multi-threaded exploitation for speed
- Stealth Mode: Low-profile exploitation with evasion
- Intelligent Selection: Browser detection-based chain selection
Architecture