
Browser-Pwning-
A proper well structured documentation for getting started with chrome pwning & v8 pwning

A proper well structured documentation for getting started with chrome pwning & v8 pwning

Detailed proof-of-concept and technical analysis for CVE-2026-2441, a Chrome CSS use-after-free vulnerability enabling sandboxed renderer RCE via…

Integer overflow in FreeType software, which also affects Chrome

Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

Google Chrome CVE-2026-6307 PoC

Proof-of-concept trigger for CVE-2026-85045, a Chrome V8 Maglev deoptimization bug causing incorrect array output on vulnerable builds.

Reproducer and technical analysis for CVE-2026-85048, a Chrome viz surface use-after-free in the GPU process, with ASAN unit tests and browser…

Full-chain Chrome exploit targeting CVE-2019-5782 and CVE-2019-13768 with custom ROP gadgets and shellcode for arbitrary command execution on Windows…

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

Proof-of-concept exploit for CVE-2026-85046 in Chrome 152.0.7977.75, demonstrating type confusion in sort() to achieve arbitrary code execution via a…

Proof-of-concept exploit collection targeting Linux kernel LPE, sudo heap overflow, and Chrome V8 OOB write vulnerabilities for penetration testing.

This project is a research-oriented and educational simulation designed to demonstrate the concept of a sandbox escape vulnerability within Google…

A collection of web browser CTF challenges and solutions.

PoC for a Chrome integer overflow -> OOB write vulnerability I reported to Google in Skia.

Chained Chrome V8 renderer escape proof-of-concept exploiting four CVEs: Float64Array corruption, Wasm overwrite, popup navigation retargeting, and…

Proof-of-concept exploit for CVE-2021-38001, a Chrome V8 JavaScript engine vulnerability, demonstrating remote code execution via crafted .mjs files.

PoC for a Chrome integer overflow -> OOB write vulnerability I reported to Google in Skia.

Proof-of-concept exploit for CVE-2023-3079, a Chrome V8 type confusion vulnerability, with curated writeups and root cause analysis resources.