
CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.
Chained Chrome V8 renderer escape proof-of-concept exploiting four CVEs: Float64Array corruption, Wasm overwrite, popup navigation retargeting, and…

Chained Chrome V8 renderer escape proof-of-concept exploiting four CVEs: Float64Array corruption, Wasm overwrite, popup navigation retargeting, and…

Proof-of-concept trigger for CVE-2026-85045, a Chrome V8 Maglev deoptimization bug causing incorrect array output on vulnerable builds.

Reproducer and technical analysis for CVE-2026-85048, a Chrome viz surface use-after-free in the GPU process, with ASAN unit tests and browser…

Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

Proof-of-concept exploit for CVE-2026-85046 in Chrome 152.0.7977.75, demonstrating type confusion in sort() to achieve arbitrary code execution via a…

Proof-of-concept and technical analysis for CVE-2026-85046, a V8 type confusion in inline Array.prototype.sort, including root cause, patch diff, and…

Proof-of-concept exploit for CVE-2026-72744, an information disclosure vulnerability in Nuxt dev server's Chrome DevTools workspace endpoint.…

Root-cause analysis and working exploit for CVE-2026-78938, a V8 TurboFan type confusion leading to arbitrary read/write within the compressed heap.…

Proof-of-concept for Chrome V8 zero-day CVE-2026-85046, providing educational exploit code and setup instructions for authorized security research in…

Reproduces CVE-2023-4357 in Google Chrome to demonstrate XML/XSLT-based file access bypass, with analysis and proof-of-concept for educational…

Exploit for Chrome V8 type confusion (CVE-2024-12381) with JSPI sandbox bypass, delivering RCE via a Flask server that fingerprints browsers and…

Proof-of-concept exploit for CVE-2026-2441, a Chrome CSS Use-After-Free in Blink CSSFontFeatureValuesMap, achieving renderer RCE via V8…

Educational presentation analyzing CVE-2021-21193, a use-after-free vulnerability in Google Chrome's Blink engine, including exploitation details and…

Proof-of-concept exploit for CVE-2026-4447, a V8 RCE in Google Chrome prior to 146.0.7680.153, allowing arbitrary code execution via crafted HTML…

Proof-of-concept for CVE-2026-2441, a Chrome CSS use-after-free leading to sandboxed renderer RCE. Includes three trigger methods, heap grooming, and…

PoC de CVE-2026-0628: inyeccion de scripts en paginas privilegiadas via webview en Chrome (CWE-862).

Reproduction case for CVE-2023-4357, a Chrome XXE vulnerability enabling arbitrary file read, with proof-of-concept files and a hosted test page.

Differential detection harness for CVE-2026-76036, a Dawn WebGPU heap buffer overflow in Chrome on Android. Probes vulnerable depth/stencil texture…