browser-exploitation

Featured

Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, renderer-to-browser sandbox escape (Mojo IPC, GPU/Dawn/ANGLE), Electron/webview IPC abuse, 1-click RCE chains

Web & Frontend 382 stars 66 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 95/100

Stars 20%
86
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Browser & Client-Side Exploitation Turn a single client-side bug into full host compromise. The modern browser is a chain target: a JS-engine bug yields an in-renderer arbitrary read/write, the V8 heap sandbox must be escaped to get a native R/W, then a second logic/memory bug in a privileged process (browser broker, GPU) escapes the OS sandbox. Electron and embedded webviews collapse several of these steps. Every cluster pairs the offensive primitive with renderer-crash/IPC telemetry, Sigma/EDR detection, and cleanup OPSEC. ## When to Activate - A V8/JavaScriptCore bug (type confusion, OOB, UAF, JIT mis-speculation) must become `addrof`/`fakeobj` and an in-renderer arbitrary R/W. - An in-renderer R/W exists but is trapped inside the **V8 heap sandbox** (pointer compression) and needs a trusted-pointer / Wasm-object escape to native memory. - A renderer is fully compromised and you need to escape the **OS sandbox** via Mojo IPC handle/logic bugs or the GPU process (Dawn/WebGPU, ANGLE). - Auditing or exploiting an **Electron / CEF / WebView2** app: `contextIsolation`/`nodeIntegration`/`sandbox` misconfig, preload-bridge & IPC abuse, ASAR/fuse/snapshot tampering. - Assembling a **1-click drive-by RCE chain** (renderer → sandbox escape → host) for an authorized red-team delivery, or doing cross-engine (Safari/JSC) work. - Patch-diffing a Chrome/V8/WebKit security release to build an n-day client-side exploit. ## Technique Map | Technique | ATT&CK | CWE | Reference | Scrip...

Details

Author
hypnguyen1209
Repository
hypnguyen1209/offensive-claude
Created
4 months ago
Last Updated
5 days ago
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category