
beef
The Browser Exploitation Framework Project

The Browser Exploitation Framework Project

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Proof of concept for CVE-2022-1364 against Alibaba's UC Browser

Windows proof-of-concept exploit chain for CVE-2019-11707, a Firefox IonMonkey type confusion, combining browser RCE with sandbox escape to achieve…

Proof-of-concept exploit for CVE-2019-13720, a Chrome browser vulnerability. Includes a demonstration video and a released exploitation tool for…

This Python script exploits a vulnerability (CVE-2024-21388) in Microsoft Edge, allowing silent installation of browser extensions with elevated…

Proof-of-concept exploit for CVE-2025-14174, a use-after-free in Chrome's V8 engine. Includes JavaScript PoC and HTML embed for identifying the…

Proof-of-concept exploit for CVE-2026-54088, a pre-authentication OS command injection in File Browser <=2.63.5. Demonstrates shell injection via…

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

Proof-of-concept exploit for CVE-2023-41993, a WebKit vulnerability in iOS 17.0 and macOS 14.0, demonstrating addrof/fakeobj primitives for browser…

Havoc C2 plugin that creates a hidden Windows desktop, streams it to a browser viewer, and injects mouse/keyboard input for covert remote control.

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

A tool to transform Chromium browsers into a C2 Implant

PoC - Exploit Delivery via Steganography and Polyglots, CVE-2014-0282

This tool is a Proof of Concept (PoC) intended for security research and educational purposes only. Using this tool on systems without explicit…

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers