
cve-2020-16012
PoC for CVE-2020-16012, a timing side channel in drawImage in Firefox & Chrome

PoC for CVE-2020-16012, a timing side channel in drawImage in Firefox & Chrome

CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)

Proof-of-concept exploit chain for Firefox JIT CVE-2026-2764, chaining JIT miscompilation and use-after-free into arbitrary read/write and WASM…

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

Proof-of-concept exploit for CVE-2016-9079 targeting Firefox on Ubuntu x64, demonstrating a use-after-free vulnerability in the SVG animation…

PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios…

PoC for CVE-2020-16012, a timing side channel in drawImage in Firefox & Chrome

An updated collection of resources targeting browser-exploitation.

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

A collection of web browser CTF challenges and solutions.

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

Exploit for CVE-2019-9810 Firefox on Windows 64-bit.

PoC for CVE-2018-18500 - Firefox Use-After-Free

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process…