
CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM-
Windows proof-of-concept exploit chain for CVE-2019-11707, a Firefox IonMonkey type confusion, combining browser RCE with sandbox escape to achieve…

Windows proof-of-concept exploit chain for CVE-2019-11707, a Firefox IonMonkey type confusion, combining browser RCE with sandbox escape to achieve…

Reproducer and technical analysis for CVE-2026-85048, a Chrome viz surface use-after-free in the GPU process, with ASAN unit tests and browser…

Exploit for CVE-2026-40369 that leverages kernel address leak and token forging to achieve privilege escalation in a browser sandbox environment.

Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render…

Docker-based lab to reproduce CVE-2023-4863 (heap buffer overflow in libwebp) with automated crash demonstration, patched vs vulnerable comparison,…

Step-by-step reproduction guide for CVE-2024-37742, a clipboard exploit in Safe Exam Browser (SEB) ≤ 3.5.0 on Windows, with PoC code and analysis.

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…

Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…

Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.

Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.

Curated collection of V8 sandbox escape, bypass, and violation reports with issue tracker links, articles, papers, slides, and design documents for…

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

Proof of concept (exploit) for CVE-2024-6473

My proof of concept for CVE-2019 Microsoft-Edge

Exploit for CVE-2024-5274, a Chrome V8 DCHECK bytecode mismatch vulnerability that provides out-of-bounds read/write primitives for browser…

High CVE-2024-4761 Exploit

Personal collection of exploits including n-days, 0-days, CTFs, kernel and browser vulnerabilities for security research and penetration testing.

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…