
WizardOpium
Google Chrome Use After Free

Google Chrome Use After Free

Proof-of-concept and technical analysis for CVE-2026-85046, a V8 type confusion in inline Array.prototype.sort, including root cause, patch diff, and…

Chained Chrome V8 renderer escape proof-of-concept exploiting four CVEs: Float64Array corruption, Wasm overwrite, popup navigation retargeting, and…

Google Chrome Vulnerabilities CVE-2021-30573

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

Reproducer and technical analysis for CVE-2026-85048, a Chrome viz surface use-after-free in the GPU process, with ASAN unit tests and browser…

Proof-of-concept trigger for CVE-2026-85045, a Chrome V8 Maglev deoptimization bug causing incorrect array output on vulnerable builds.

Chromium Browser DoS Attack via document.title Exploitation

Proof-of-concept exploit for CVE-2021-30573, a use-after-free vulnerability in Google Chrome's GPU component allowing remote heap corruption via…

Root-cause analysis and working exploit for CVE-2026-78938, a V8 TurboFan type confusion leading to arbitrary read/write within the compressed heap.…

Chrome extension and Shodan scanner for detecting and demonstrating RCE vulnerabilities in React Server Components (RSC) and Next.js applications,…

A Chrome extension static analysis tool to help aide in security reviews.

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

Curated proof-of-concept exploits for real-world CVEs affecting iOS, macOS, Chrome Renderer, and Steam clients, with version-specific targets and…

Chrome V8 n-day exploits that I've written.

A proper well structured documentation for getting started with chrome pwning & v8 pwning

PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp)

Chrome < 62 uxss exploit (CVE-2017-5124)