
browser-pwn
An updated collection of resources targeting browser-exploitation.

An updated collection of resources targeting browser-exploitation.

Curated collection of V8 sandbox escape, bypass, and violation reports with issue tracker links, articles, papers, slides, and design documents for…

Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…

SetCookie Analysis in Browser Research Results

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

A Documentation of CVE-2025-68116

Proof of concept exploit for CVE-2012-1723

(CVE-2023-31290) Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the…

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

Technical analysis of CVE-2017-0037, a Microsoft browser memory corruption vulnerability enabling remote code execution via type confusion in CSS/JS…

An attacker can execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or privilege escalation.

Browser extension that automatically fills out cookie popups based on your preferences

A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics,…

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

PoC - Exploit Delivery via Steganography and Polyglots, CVE-2014-0282

NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation

Analysis of DataDome's custom obfuscated VM and bytecode format, revealing string encryption, S-box ciphers, and browser fingerprinting signals for…