
CVE-2019-5786 および CVE-2019-0808 Chrome 72.0.3626.119 安定版 Windows 7 x86 エクスプロイトチェーン。
このエクスプロイトは、サイト分離を使用して CVE-2019-5786 をブルートフォースします。 host1_wrapper/iframe.html は、エクスプロイトを iframe に繰り返し読み込むラッパースクリプトです。実際のチェーンは host2_single_run ディレクトリにあります。CVE-2019-0808 のサンドボックスエスケープエクスプロイトは、ファイル host2_single_run/shellcode.js にあり、その .dll 形式から [sRDI][https://github.com/monoxgas/sRDI] および msfvenom を介して変換されています。
host1_wrapper ディレクトリの内容を提供し、もう一方のサイトで host2_single_run の内容を提供します。host1_wrapper/iframe.html の 14 行目を host2_single_run/exploit.html の URL に変更します。