
Source
Development has moved to https://codeberg.org/librewolf/source

PoC for CVE-2022-28281 a Mozilla Firefox Out of bounds write.

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Hardened Android web browser forked from Mull/Firefox with privacy-focused patches, anti-fingerprinting, telemetry removal, and secure defaults for…

Bitwarden client apps (web, browser extension, desktop, and cli).

Exploit code for CVE-2016-9066

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

Proof-of-concept exploit code for Firefox CVEs (2022-1802, 1529, 2200) targeting version 100.0.1 on Windows, demonstrating browser vulnerability…

Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu

Remote access trojan created using WinRar with firefox installer and python Reverse Shell embedded.

Proof-of-concept exploit for CVE-2022-26485 targeting Firefox 78.0 on Windows, demonstrating a remote code execution vulnerability in the browser's…

PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于…

PoC for CVE-2020-16012, a timing side channel in drawImage in Firefox & Chrome

Proof-of-concept exploit for CVE-2016-9079 targeting Firefox on Ubuntu x64, demonstrating a use-after-free vulnerability in the SVG animation…

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

CVE-2026-74970, Fission site isolation bypass in Firefox WebRender

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…