
CVE-2026-12295-UXXS-in-my-wasm
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process…

Full Firefox chain: CVE-2026-2796 wasm type confusion -> content-process RCE, plus CVE-2026-2768 parent-process escape analysis (both fixed in…

Proof-of-concept exploit for CVE-2019-17026, a Firefox vulnerability enabling arbitrary code execution via crafted JavaScript.

Proof-of-concept exploit chain for Firefox JIT CVE-2026-2764, chaining JIT miscompilation and use-after-free into arbitrary read/write and WASM…

Critical CVE-2025-4322 exploit for Firefox on Windows enabling sandbox escape and arbitrary code execution. Includes download link and technical…

CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)

Chrome and Firefox extension that lists Amazon S3 Buckets while browsing

PoC for CVE-2018-18500 - Firefox Use-After-Free

Example of exploiting CVE-2011-3026 on Firefox (Linux/x86)

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

Hands-on lab for CVE-2024-4367, demonstrating PDF.js font rendering vulnerability exploitation in Firefox. Includes PoC generator, vulnerable and…

Proof-of-concept for CVE-2021-43530, a Universal XSS vulnerability in Firefox for Android caused by improper URL sanitization when processing QR code…

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

CVE-2018-12386 - Firefox Sandboxed RCE Exploit for Linux (Firefox <v62.0.3)

CVE-2018-12386 - Firefox Sandboxed RCE Exploit for Linux (Firefox <v62.0.3)

PoC for CVE-2020-16012, a timing side channel in drawImage in Firefox & Chrome

Proof-of-concept demonstrating a Use-After-Free vulnerability in Firefox's RTCEncodedFrameBase via WebRTC Encoded Transforms, enabling heap…