
rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android
Differential detection harness for CVE-2026-76036, a Dawn WebGPU heap buffer overflow in Chrome on Android. Probes vulnerable depth/stencil texture…

Differential detection harness for CVE-2026-76036, a Dawn WebGPU heap buffer overflow in Chrome on Android. Probes vulnerable depth/stencil texture…

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

The above investigation of the ES file browser security weakness allows us to see the issue in its entirety

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…

Hardened Android web browser forked from Mull/Firefox with privacy-focused patches, anti-fingerprinting, telemetry removal, and secure defaults for…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Proof-of-concept exploit for Same-Origin Policy bypass in Samsung Internet Browser for Android, demonstrating a cross-origin data access…

Interact with Frida devices, processes, and scripts directly from your browser.

Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…

Proof-of-concept exploit for CVE-2022-1364 targeting Chromium-based Bromite on Android (arm_ChromePublic.apk), demonstrating a browser memory-safety…

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

Reporte técnico sobre vulnerabilidad crítica de Xiaomi