Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
V8-sbx-bypass-collection — Curated collection of V8 sandbox escape, bypass, and violation reports with issue tracker links, articles, papers, slides, and design documents for advanced browser exploitation research. | Kitploit
Tools/GitHubGitHub/xv0nfers/v8-sbx-bypass-collection
Vulnerability AnalysisExploitationWeb SecurityPapers & ResearchCurated ResourcesBinary Exploitation
GitHubxv0nfers/v8-sbx-bypass-collection

V8-sbx-bypass-collection

Curated collection of V8 sandbox escape, bypass, and violation reports with issue tracker links, articles, papers, slides, and design documents for advanced browser exploitation research.

View Repository
2923031 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

V8 Sandbox escape/bypass/violation and VR collection

A collection of links related to V8 sandbox VR and exploitation

Contents

  • IssueTracker
  • Articles
  • Papers & Slides
  • Design documents

IssueTracker

2023: "issue id: 40940619, V8 Sandbox escape due to type tags in ExternalPointerTable being too coarse for Embedder Objects"

2023: "issue id: 40940623, V8 Sandbox escape due to coarse type-checking for Foreigns"

2024: "issue id: 42204606, Mitigate sandbox escapes in RegExp"

2024: "issue id: 336507783, V8 Sandbox: Prevent Wasm-based sandbox escapes "

2024: "issue id: 327732554, V8 sandbox violation due to signed comparison of (untrusted) string length against buffer size"

2024: "issue id: 326086002, Sandbox violations due to (exhaustive) switches over enums when the code after the switch has UB"

2024: "issue id: 327732554, V8 sandbox violation in v8::internal::Builtins::code"

2024: "issue id: 328692018, V8 sandbox violation in v8::bigint::Digits::read_4byte_aligned"

2024: "issue id: 328858270, V8 sandbox violation in v8::internal::GetBailoutReason"

2024: "issue id: 332475841, V8 sandbox violation in v8::internal::ElementsKindToString"

2024: "issue id: 41487854, V8 sandbox violation in Builtins_StarWideHandler"

2024: "issue id: 323736727, V8 sandbox violation in Builtins_DeoptimizationEntry_Eager"

2024: "issue id: 323694399, V8 sandbox violation in Builtins_DeoptimizationEntry_Eager"

2024: "issue id: 323696394, V8 sandbox violation in Builtins_DeoptimizationEntry_Eager"

2024: "issue id: 323690010, V8 sandbox violation in Builtins_DeoptimizationEntry_Eager"

2024: "issue id: 327550517, V8 sandbox violation in v8::internal::ArrayBufferSweeper::Detach"

2024: "issue id: 324343442, V8 sandbox violation in v8::internal::SemiSpace::FixPagesFlags"

2024: "issue id: 324482838, V8 sandbox violation in v8::internal::maglev::MaglevGraphBuilder::BuildAllocateFastObject"

2024: "issue id: 326109866, Use-after-poison in v8::internal::compiler::MapData::instance_type"

2024: "issue id: 327719160, V8 sandbox violation in v8::internal::MarkCompactCollector::ProcessMarkingWorklist"

2024: "issue id: 327827222, V8 sandbox violation in v8::internal::ConcurrentMarking::RunMajor"

2024: "issue id: 329425726, V8 sandbox violation in v8::internal::Scavenger::IterateAndScavengePromotedObject"

2024: "issue id: 329886545, V8 sandbox violation in v8::internal::JSFunction::CalculateExpectedNofProperties"

2024: "issue id: 330219140, V8 sandbox violation in unsigned int v8::base::AsAtomicImpl::Relaxed_Load"

2024: "issue id: 330385840, V8 sandbox violation in v8::internal::Code::kind"

2024: "issue id: 330404819, V8 Sandbox escape via regexp"

2024: "issue id: 329781445, V8 sandbox violation in v8::internal::Scavenger::IterateAndScavengePromotedObject"

2024: "issue id: 330563095, WebCodecs VideoFrame Race Condition UAF Write to RCE" by Seunghyun Lee(@0x10n) [Pwn2Own 2024]

2024: "issue id: 331042197, V8 sandbox violation in v8::internal::Scavenger::IterateAndScavengePromotedObject"

2024: "issue id: 330922416, V8 sandbox violation in v8::internal::ArrayBufferExtension::backing_store"

2024: "issue id: 331036491, V8 sandbox violation in icu_73::Locale::getBaseName"

2024: "issue id: 330096629, V8 sandbox violation in icu_73::RelativeDateTimeFormatter::getFormatStyle"

2024: "issue id: 331241020, V8 sandbox violation and memory corruption due to buffer overflow in compiler"

2024: "issue id: 331883947, V8 sandbox violation in v8::internal::Managed<icu_73::Locale>::GetSharedPtrPtr"

2024: "issue id: 331837303, V8 sandbox violation in v8::internal::maglev::MaglevGraphBuilder::TryBuildInlinedAllocatedContext"

2024: "issue id: 331042216, V8 sandbox violation in v8::internal::LazyCreateDateIntervalFormat"

2024: "issue id: 333065495, V8 sandbox violation in v8::internal::MemoryChunkMetadata::heap"

2024: "issue id: 329920544, V8 sandbox violation in v8::internal::Managed<icu_73::number::LocalizedNumberFormatter>::GetSharedPtrPtr"

2024: "issue id: 330800450, V8 sandbox violation in unsigned long v8::base::AsAtomicImpl::Relaxed_Load"

2024: "issue id: 335763881, V8 sandbox violation in v8::internal::TranslatedState::CreateNextTranslatedValue"

2024: "issue id: 335544065, V8 sandbox violation in Builtins_DeoptimizationEntry_Eager"

2024: "issue id: 335322609, V8 sandbox violation in v8::internal::maglev::CapturedObject::set"

2024: "issue id: 335810507, V8 sandbox violation in v8::internal::ToLatin1Lower"

2024: "issue id: 337094992, V8 sandbox violation in v8::internal::ArrayBufferExtension::backing_store"

2024: "issue id: 336655186, V8 sandbox violation in v8::internal::Scavenger::IterateAndScavengePromotedObject"

2024: "issue id: 333829668, V8 sandbox violation in v8::base::Flags<v8::internal::MemoryChunk::Flag, unsigned long, unsigned long>::"

2024: "issue id: 327473161, V8 sandbox violation in v8::internal::TranslatedState::CreateNextTranslatedValue"

2024: "issue id: 334120897, V8 Sandbox Bypass: wasm function signature confusion leading to out of sandbox arbitrary read/write "

2024: "issue id: 336648007, V8 sandbox violation in v8::internal::maglev::CapturedObject::set"

2024: "issue id: 343407073, V8 Sandbox Bypass: control-flow hijacking via WASM Table Indirect call"[Edouard Bochin (@le_douds) and Tao Yan (@Ga1ois)]

2024: "issue id: 339141292, V8 sandbox violation in Builtins_JSToJSWrapper"

2024: "issue id: 339310133, V8 sandbox violation in v8::internal::maglev::CapturedObject::set"

2024: "issue id: 339517309, V8 sandbox violation in v8::internal::maglev::CapturedObject::set"

2024: "issue id: 338342089, V8 sandbox violation in v8::internal::wasm::name"

2024: "Generate heap sandbox tags for IDL-based types"

2024: "issue id: 337941142, V8 sandbox violation in v8::base::Flags<v8::internal::MemoryChunk::Flag, unsigned long, unsigned long>::"

2024: "issue id: 342451736, V8 sandbox violation in void v8::internal::BodyDescriptorBase::IterateTrustedPointer<v8::internal::MainM "

2024: "issue id: 342866373, V8 Sandbox Bypass: JSToWasmWrapperAsm accessible and allows type confusion"

2024: "issue id: 338342091, V8 sandbox violation in Builtins_JSToJSWrapper"

2024: "issue id: 337547182, V8 sandbox violation in Builtins_SuspendGeneratorHandler"

2024: "issue id: 342297062, V8 sandbox violation if SFI::formal_parameter_count doesn't match the parameter count of a function's code"

2024: "issue id: 343801366, V8 Sandbox Bypass: Incomplete hardening of the experimental regex engine"

2024: "issue id: 344943044, V8 sandbox violation in v8::internal::maglev::MaglevGraphBuilder::GetValueNodeFromCapturedValue"

2024: "issue id: 344963941, V8 Sandbox Bypass: Irregexp engine bytecode modification leads to arbitrary read/write outside the sandbox"

2024: "issue id: 346799730, Regexp backtrack stack can underflow"

2024: "issue id: 339043698, V8 sandbox violation in unsigned char v8::base::ReadUnalignedValue"

2024: "issue id: 348324480, OutsideSandboxOrInReadonlySpace checks in-sandbox data"

2024: "issue id: 349517592, Wasm FeedbackMaker OOB accesses"

2024: "issue id: 345547973, V8 sandbox violation in v8::internal::wasm::name"

2024: "issue id: 349563054, V8 Sandbox Bypass: UAF by manipulating Managed"

2024: "issue id: 349641090, V8 sandbox violation in v8::internal::compiler::MapData::instance_type"

2024: "issue id: 337906704, V8 sandbox violation in v8::internal::OldLargeObjectSpace::PromoteNewLargeObject"

2024: "issue id: 348793147, V8 Sandbox Bypass: AAR/W via table import signature check bypass"

2024: "issue id: 351327767, WebAssembly OOB memory access due to cached memory index confusion"

2024: "issue id: 352446085, V8 Sandbox Bypass: AAR/W via WASM import race condition leading to broken runtime bounds check with memory64"

2024: "issue id: 349502157, V8 Sandbox Bypass: AAR/W via table set OOB SBXCHECK_LT() bypass"

2024: "issue id: 349529650, V8 Sandbox Bypass: AAR/W via function import signature check race"

2024: "issue id: 352689356, V8 Sandbox Bypass: AAR/W via WASM function signature confusion in TurboFan call_ref"

2024: "issue id: 372298915, V8 sandbox violation in v8::internal::BuiltinArguments::operator "

2024: "issue id: 356649155, V8 sandbox violation in v8::internal::OldLargeObjectSpace::PromoteNewLargeObject"

2024: "issue id: 329345899, V8 sandbox violation due to OOB SlotSet Bucket access when heap memory is corrupted"

2024: "issue id: 341129593, V8 Sandbox Bypass: Interpreted Function Argument Mismatch"

2024: "issue id: 344343031, V8 Sandbox Bypass: Code Pointer Table Index Confusion leading to Stack Corruption"

2024: "issue id: 338381304, V8 Sandbox Bypass: stack corruption due to parameter count mismatch"

2024: "issue id: 359952306, V8 sandbox violation in v8::internal::CommonFrameWithJSLinkage::GetParameter"

2024: "issue id: 359070975, V8 sandbox violation in unsigned int v8::internal::ReadMaybeUnalignedValue"

2024: "issue id:369652807, V8 sandbox violation in v8::internal::wasm::name"

2024: "issue id:354408144, V8 Sandbox Bypass: AAR/W via WASM signature confusion in Wasm-to-JS wrapper through PodArrayOfWasmValueType overwrite"

2024: "issue id:348084786, V8 Sandbox Bypass: with Shared Function Info"

2024: "issue id:361862752, V8 Sandbox Bypass: compiled JS-to-WASM wrappers don't guard against trusted_function_data overwrites"

2024: "issue id:372749557, V8 sandbox violation in Builtins_SuspendGeneratorBaseline"

2024: "issue id:366374966, V8 sandbox violation in Builtins_CEntry_Return1_ArgvOnStack_BuiltinExit"

2024: "issue id:376496315, V8 sandbox violation in v8::internal::TranslatedValue::kind"

2024: "issue id:379768241, V8 sandbox violation in v8::internal::SlotSet* v8::internal::MutablePageMetadata::slot_set<"

2024: "issue id:379418918, V8 sandbox violation in Builtins_ContinueToJavaScriptBuiltinWithResult"

2024: "issue id:374812612, V8 Sandbox violation during OSR tier-up if code on FeedbackVector is modified"

2024: "issue id:381127888, V8 sandbox violation in v8::internal::compiler::JSContextSpecialization::ReduceJSLoadScriptContext"

2024: "issue id:350628675, V8 Sandbox Bypass: AAR/W via WASM dispatch table index OOB from `WasmTableObject.uses'"

2024: "issue id:382147423, V8 sandbox violation in v8::internal::MutablePageMetadata::SweepingDone"

2024: "issue id:381999810, V8 Sandbox Bypass: Memory corruption outside the V8 sandbox"

2024: "issue id:350292240, V8 Sandbox Bypass: AAR/W via generic function table call_indirect rtt check bypass"

2024: "issue id:384186547, V8 Sandbox Bypass: Attacker manipulation of ArrayBufferSweeper linked lists results in dangling ArrayBufferExtension pointers"

2025: "issue id:389713719, V8 Sandbox Bypass: MemoryChunk metadata_pointer_table OOB write"

2025: "issue id:388437270, V8 Sandbox Bypass: OOB write in JsonStringifier::SerializeString"

2025: "issue id:389970331, V8 Sandbox Bypass: StringToBigIntHelper stack-buffer-overflow"

2025: "issue id:390568183, V8 Sandbox Bypass: UB in MessageHandler::GetMessage because of invalid MessageTemplate variant"

2025: "issue id:390453039, V8 Sandbox Bypass: UB in WebAssemblyMemoryGrow because AddressType is constructed from on-heap data"

2025: "issue id:390816209, V8 Sandbox Bypass: Control flow hijack via switch-case over corrupted MessageTemplate enum value"

2025: "issue id:390441099, V8 Sandbox Bypass: StringToBigIntHelper stack-buffer-overflow"

2025: "V8 Sandbox Bypass: AAW (wildcopy) due to %TypedArray%.prototype.set bounds check integer overflow"

2025: "issue id:395659804, V8 Sandbox Bypass: Arbitrary code execution via OSR DeoptimizationData confusion"

2025: "issue id:398773898, V8 Sandbox Bypass: OOB write in JsonStringifier::TrySerializeSimplePropertyKey"

2025: "issue id:393989622, V8 sandbox violation in icu_74::UnicodeString::doAppend"

2024: "issue id:385775375, V8 sandbox violation due to concurrent ArrayBuffer modifications during std::sort"

2024: "issue id:386565139, V8 Sandbox Bypass: Interger Overflow in TypedArraySet leading to out-of-sandbox write"

2025: "issue id:403600260, V8 Sandbox Bypass: Uninitialized read to switch-case OOB jump in Maglev JSGeneratorObject allocation inlining"

2025: "issue id:401732698, V8 sandbox violation in v8"

2025: "issue id:404285918, V8 Sandbox Bypass: SP/PC control via Wasm JSPI central stack top confusion"

2025: "issue id:396446145, V8 Sandbox Bypass: OOB write in JsonParser::DecodeString (double fetch)"

2025: "issue id:395895382, V8 Sandbox Bypass: AAW via array length corruption in Turbofan spread call inlining"

Articles

2022: "Code Execution in Chromium’s V8 Heap Sandbox"

2022: "KITCTFCTF 2022 V8 Heap Sandbox Escape"

2022: "memory hole"[DiceCTF 2022]

2022: "Memory Hole: Breaking V8 Heap Sandbox"[DiceCTF 2022]

2023: "Use Native Pointer of Function to Bypass The Latest Chrome v8 Sandbox (exp of issue1378239)"

2023: "Use Wasm to Bypass Latest Chrome v8sbx Again"

2023: "Exploiting Zenbleed from Chrome"

2023: "Exploring Historical V8 Heap Sandbox Escapes I"

2023: "Abusing Liftoff assembly and efficiently escaping from sbx(@r3tr074)"

2023: "Start Your Engines - Capturing the First Flag in Google's New v8CTF"

2024: "Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution"

2024: "The V8 Sandbox"

2024: "Issue-1472121 : Exploit out-of-bound CloneObjectIC type confusion"

2024: "From object transition to RCE in the Chrome renderer"

2024: "Attack of the clones: Getting RCE in Chrome’s renderer with duplicate object properties"

2024: "A Deep Dive into V8 Sandbox Escape Technique Used in In-The-Wild Exploit"

2024: "CVE-2024-2887: A Pwn2Own Winning Bug in Google Chrome"

2024: "Breaking V8 Sandbox with Trusted Pointer Table"[HITCON CTF 2024]

2024: "HITCON CTF QUAL 2024 Pwn Challenge Part 1 - Halloween and v8sbx"[HITCON CTF 2024]

2024: "SSD Advisory – Google Chrome RCE(Seunghyun Lee (@0x10n)"[TyphoonPWN 2024]

Papers & Slides

2022: "Sandboxing V8(Samuel Groß, @5aelo)"

2023: "Modern chrome exploit chain development"[POC2023 - @numencyber]

2024: "The V8 Heap Sandbox(Samuel Groß, @5aelo)"[OffensiveCon 2024]

2024: "A Chrome/Edge RCE via V8 WASM Type Confusion by Manfred Paul(@_manfp)"[Pwn2Own Vancouver 2024]

2024: "Google Chrome Renderer Only RCE by Seunghyun Lee (@0x10n)"[Pwn2Own Vancouver 2024]

2024: "Evolution of the protections of the V8 JSE"[slides][Full Article][SSTIC2024]

2024: "From the Vulnerability to the Victory: A Chrome Renderer 1-Day Exploit’s Journey to v8CTF Glory"[TyphoonCon 2024]

2024: "TIKTAG: Breaking ARM’s Memory Tagging Extension with Speculative Execution"

2024: "Let the Cache Cache and Let the WebAssembly Assemble: Knockin' on Chrome's Shell"[blackhat USA 2024]

2024: "V8 Sandbox Escape Write Up - Edouard Bochin (@le_douds) and Tao Yan (@Ga1ois)"[Pwn2Own Vancouver 2024]

2024: "Bypassing the V8 sandbox protection mechanism"[OFFZONE 2024]

2024: "Chrome Exploitation: from Zero to Heap-Sandbox Escape"[BSides Oslo 2024][matteo malvica]NDC Security 2025

2024: "WebAssembly Is All You Need: Exploiting Chrome and the V8 Sandbox 10+ times with WASM"[POC2024][Seunghyun Lee]

2024: "Fake it till you make it: Bypassing V8 Sandbox by constructing a fake Isolate"[POC2024][Jaewon Min][Kaan Ezder]

Design documents

2019: "Compressed pointers in V8"

2021: "V8 Sandbox"

2022: "V8 Sandbox - Address Space"

2022: "V8 Sandbox - Sandboxed Pointers"

2022: "V8 Sandbox - External Pointer Sandboxing"

2022: "V8 Sandbox - Code Pointer Sandboxing"

2023: "V8 Sandbox - Glossary"

2023: "V8 Sandbox - Trusted Space"

2024: "Multiple sandboxes aka sandbox per isolate group"

2024: "V8 Sandbox - Hardware Support"

2024: "V8 Sandbox - Embedder Pointer Sandboxing"

2024: "V8 Sandbox + Leaptiering"

2025: "V8 Sandbox - Hardware Sandbox v0.1"

Download Tool