
browser-security-project
Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

An updated collection of resources targeting browser-exploitation.

A collection of web browser CTF challenges and solutions.

Phishing simulation and awareness framework for node-based campaigns, credential capture, SMTP delivery, CAPTCHA, and optional browser credential…

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…

SetCookie Analysis in Browser Research Results

Some Generic Browser Exploits (For Educational Purposes Only)

camjacking templates

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata


Educational resource on Cross-site Scripting (XSS) attack techniques, covering non-persistent, persistent, and DOM-based vectors with practical…

Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.

:muscle: Proof Of Concept of the BEAST attack against SSL/TLS CVE-2011-3389 :muscle:

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

A Chrome extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications

Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation