
browser-pwn
An updated collection of resources targeting browser-exploitation.
binary-exploitationctfcurated-resources+4
830

An updated collection of resources targeting browser-exploitation.

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

Example of exploiting CVE-2011-3026 on Firefox (Linux/x86)

CVE-2018-12386 - Firefox Sandboxed RCE Exploit for Linux (Firefox <v62.0.3)

PoC for CVE-2020-16012, a timing side channel in drawImage in Firefox & Chrome

Proof-of-concept demonstrating a Use-After-Free vulnerability in Firefox's RTCEncodedFrameBase via WebRTC Encoded Transforms, enabling heap…