
WizardOpium
Google Chrome Use After Free

Google Chrome Use After Free

Chained Chrome V8 renderer escape proof-of-concept exploiting four CVEs: Float64Array corruption, Wasm overwrite, popup navigation retargeting, and…

Reproducer and technical analysis for CVE-2026-85048, a Chrome viz surface use-after-free in the GPU process, with ASAN unit tests and browser…

Proof-of-concept trigger for CVE-2026-85045, a Chrome V8 Maglev deoptimization bug causing incorrect array output on vulnerable builds.

Root-cause analysis and working exploit for CVE-2026-78938, a V8 TurboFan type confusion leading to arbitrary read/write within the compressed heap.…

Proof-of-concept exploit collection targeting Linux kernel LPE, sudo heap overflow, and Chrome V8 OOB write vulnerabilities for penetration testing.

Curated proof-of-concept exploits for real-world CVEs affecting iOS, macOS, Chrome Renderer, and Steam clients, with version-specific targets and…

Chrome V8 n-day exploits that I've written.

Chrome v8 1Day Exploit by István Kurucsai

A proper well structured documentation for getting started with chrome pwning & v8 pwning

Proof-of-concept exploit for CVE-2023-3079, a Chrome V8 type confusion vulnerability, with curated writeups and root cause analysis resources.

Integer overflow in FreeType software, which also affects Chrome

Google Chrome CVE-2026-6307 PoC

Exploit for CVE-2024-5274, a Chrome V8 DCHECK bytecode mismatch vulnerability that provides out-of-bounds read/write primitives for browser…

Chrome Renderer 1day RCE via Type Confusion in Async Stack Trace (v8ctf submission)

my exp for chrome V8 CVE-2021-30551

Chrome V8 RCE exploit for CVE-2021-30632 targeting Windows systems. Tested on Chrome 91-93. Includes JS POC and in-the-wild bug analysis reference.

Proof-of-concept exploit for CVE-2021-38001, a Chrome V8 JavaScript engine vulnerability. Demonstrates exploitation via d8 shell with a malicious…