browser-exploitation
Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, renderer-to-browser sandbox escape (Mojo IPC, GPU/Dawn/ANGLE), Electron/webview IPC abuse, 1-click RCE chains
Install / Use
npx skills add hypnguyen1209/offensive-claude --skill browser-exploitationInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Tags
Our assessment of browser-exploitation
browser-exploitation scores 86/100 on our quality scale, 714th of 1,096 Security skills we index.
Its SKILL.md is 9.6 KB long, well organised into 16 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
It has 377 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 14 days ago, so browser-exploitation is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
browser-exploitation compared with similar skills
All 4 of these similar skills score higher than browser-exploitation; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| browser-exploitation (this skill)by hypnguyen1209 | 86 | 377 | 14d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 13d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 13d ago | SKILL.md |
Frequently asked questions
- How do I install browser-exploitation?
- Run
npx skills add hypnguyen1209/offensive-claude --skill browser-exploitation. The install tabs above show the steps for each supported agent. - Which AI agents does browser-exploitation work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is browser-exploitation safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is browser-exploitation still maintained?
- The repository was last updated 14 days ago, so browser-exploitation is actively maintained.
Skill content
View source on GitHubname: browser-exploitation description: Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, renderer-to-browser sandbox escape (Mojo IPC, GPU/Dawn/ANGLE), Electron/webview IPC abuse, 1-click RCE chains metadata: type: offensive phase: exploitation tools: d8, gdb-gef, pwndbg, lldb, WinDbg, IDA, Frida, jsvu, asar, electronegativity, Wireshark, mojo-tools mitre: [T1203, T1189, T1059.007, T1068, T1055, T1574] kill_chain: phase: [weaponize, deliver, exploit] step: [2, 3, 4] attck_tactics: [TA0042, TA0001, TA0002, TA0004] attck_techniques: [T1203, T1189, T1059.007, T1068, T1055.012, T1574.002] depends_on: [recon-osint, vulnerability-analysis, exploit-development, reverse-engineering] feeds_into: [initial-access, edr-evasion, shellcode-dev, privesc-windows, privesc-linux, red-team-ops] inputs: [target_browser_versions, vulnerability_list, crash_corpus, electron_app_build, attack_surface_map] outputs: [renderer_rw_primitive, sandbox_escape_poc, clientside_rce_chain, exploit_poc, finding_record] references:
- references/v8-jit-typeconfusion.md
- references/v8-sandbox-escape.md
- references/renderer-to-browser-escape.md
- references/electron-webview-rce.md
- references/clientside-rce-chains.md scripts:
- scripts/v8_typer.js
- scripts/sandbox_escape.js
- scripts/mojo_fuzz_harness.py
- scripts/electron_audit.py
- scripts/chain_server.py
- scripts/d8_debug.sh
Browser & Client-Side Exploitation
Turn a single client-side bug into full host compromise. The modern browser is a chain target: a JS-engine bug yields an in-renderer arbitrary read/write, the V8 heap sandbox must be escaped to get a native R/W, then a second logic/memory bug in a privileged process (browser broker, GPU) escapes the OS sandbox. Electron and embedded webviews collapse several of these steps. Every cluster pairs the offensive primitive with renderer-crash/IPC telemetry, Sigma/EDR detection, and cleanup OPSEC.
When to Activate
- A V8/JavaScriptCore bug (type confusion, OOB, UAF, JIT mis-speculation) must become
addrof/fakeobjand an in-renderer arbitrary R/W. - An in-renderer R/W exists but is trapped inside the V8 heap sandbox (pointer compression) and needs a trusted-pointer / Wasm-object escape to native memory.
- A renderer is fully compromised and you need to escape the OS sandbox via Mojo IPC handle/logic bugs or the GPU process (Dawn/WebGPU, ANGLE).
- Auditing or exploiting an Electron / CEF / WebView2 app:
contextIsolation/nodeIntegration/sandboxmisconfig, preload-bridge & IPC abuse, ASAR/fuse/snapshot tampering. - Assembling a 1-click drive-by RCE chain (renderer → sandbox escape → host) for an authorized red-team delivery, or doing cross-engine (Safari/JSC) work.
- Patch-diffing a Chrome/V8/WebKit security release to build an n-day client-side exploit.
Technique Map
| Technique | ATT&CK | CWE | Reference | Script | |-----------|--------|-----|-----------|--------| | JIT type confusion (TurboFan/Maglev/Turboshaft) | T1203 | CWE-843 | references/v8-jit-typeconfusion.md | scripts/v8_typer.js | | Element-kind confusion -> addrof/fakeobj | T1203 | CWE-843 | references/v8-jit-typeconfusion.md | scripts/v8_typer.js | | OOB read/write on JSArray/TypedArray | T1203 | CWE-787 | references/v8-jit-typeconfusion.md | scripts/v8_typer.js | | In-renderer arbitrary R/W (fake TypedArray) | T1203 | CWE-787 | references/v8-jit-typeconfusion.md | scripts/v8_typer.js | | V8 heap-sandbox escape via raw Wasm pointer | T1203 | CWE-787 | references/v8-sandbox-escape.md | scripts/sandbox_escape.js | | Trusted Pointer Table / WasmExportedFunctionData abuse | T1203 | CWE-843 | references/v8-sandbox-escape.md | scripts/sandbox_escape.js | | Code/exec via Wasm JIT region pivot | T1203 | CWE-94 | references/v8-sandbox-escape.md | scripts/sandbox_escape.js | | Mojo IPC handle-confusion sandbox escape | T1203 | CWE-269 | references/renderer-to-browser-escape.md | scripts/mojo_fuzz_harness.py | | GPU-process UAF/OOB (Dawn/WebGPU, ANGLE) | T1203 | CWE-416 | references/renderer-to-browser-escape.md | scripts/mojo_fuzz_harness.py | | Mojo interface fuzzing for broker bugs | T1203 | CWE-20 | references/renderer-to-browser-escape.md | scripts/mojo_fuzz_harness.py | | Electron contextIsolation/IPC bridge RCE | T1059.007 | CWE-1188 | references/electron-webview-rce.md | scripts/electron_audit.py | | nodeIntegration / webviewTag preload abuse | T1059.007 | CWE-829 | references/electron-webview-rce.md | scripts/electron_audit.py | | ASAR integrity / fuse / V8 snapshot tamper | T1574.002 | CWE-345 | references/electron-webview-rce.md | scripts/electron_audit.py | | XSS/open-redirect -> Electron RCE | T1189 | CWE-79 | references/electron-webview-rce.md | scripts/electron_audit.py | | 1-click drive-by chain delivery | T1189 | CWE-693 | references/clientside-rce-chains.md | scripts/chain_server.py | | Cross-engine (JSC/WebKit) primitive port | T1203 | CWE-843 | references/clientside-rce-chains.md | scripts/chain_server.py |
Quick Start
# 0. Pin the exact target build (Chrome/Edge/Electron all carry a V8 version)
# chrome://version | edge://version | electron --version
jsvu --engines=v8 # local d8 of matching version
./scripts/d8_debug.sh ./d8 ./poc.js # d8 w/ exploit-friendly flags
# 1. Engine bug -> in-renderer R/W (see references/v8-jit-typeconfusion.md)
d8 --allow-natives-syntax --shell ./scripts/v8_typer.js
# yields addrof(), fakeobj(), read64()/write64() inside the V8 heap cage
# 2. Escape the V8 heap sandbox -> native R/W (references/v8-sandbox-escape.md)
d8 --no-sandbox-testing-mode ./scripts/sandbox_escape.js # local test;
# on a real build: abuse trusted Wasm object raw pointer -> overwrite RWX Wasm code
# 3. Escape the OS sandbox: Mojo broker logic bug OR GPU-process memory bug
python3 scripts/mojo_fuzz_harness.py --interface FileSystemAccess --iters 100000
# 4. Electron / webview target: audit + weaponize
python3 scripts/electron_audit.py /path/to/app.asar # finds nodeIntegration/IPC/fuse gaps
# craft IPC/preload payload from the report; package XSS->RCE
# 5. Stage the full 1-click chain and serve it
python3 scripts/chain_server.py --stage1 renderer.js --stage2 escape.js --lhost 10.0.0.5 --lport 8080
OPSEC & Detection (summary)
| Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note |
|-----------|---------------|-----------------------|------------|
| JIT type confusion | Renderer crash dumps (chrome_crashpad, crashpad_handler), GPU/renderer restarts, *-crash in ~/AppData/Local/.../Crashpad | Sigma: spike in renderer crash reports; EDR on crashpad_handler bursts | Spray/clean up corrupted arrays; bail without crashing on failed type-check; do not leave %DebugPrint calls |
| V8 sandbox escape | Native R/W faults if math is off; abnormal RWX Wasm pages | EDR: RWX region churn inside chrome.exe/renderer; ETW VirtualProtect to RWX | Keep corruption inside the cage until the last step; reuse existing RWX Wasm code page rather than allocating new |
| Mojo broker escape | Browser process spawning cmd.exe/powershell.exe/rundll32.exe; unexpected file writes by broker | Sigma: chrome.exe/msedge.exe parent -> shell child; EDR child-process rule; Mojo message audit | Live off the broker's own capabilities (file write, process launch); avoid spawning a console child — inject instead |
| GPU-process bug | GPU process crashes (--type=gpu), Dawn/ANGLE asserts, DXGI/Metal faults | EDR on GPU-process child anomalies; WebGPU enabled via policy = surface | Test against the right GPU backend (D3D11/Metal/Vulkan); fail closed without crashing the GPU process |
| Electron IPC/preload RCE | app.asar mtime change, node child of Electron app, child_process.exec | Sigma: Electron app spawning shells; FIM on app.asar/snapshot blobs | Prefer in-process JS exec (require gadget) over child_process; restore app.asar mtime after fuse/snapshot tamper |
| Drive-by chain delivery | Suspicious text/html with large encoded JS, WebSocket/long-poll to attacker host, UA-gated content | Proxy/Sigma on long base64/%u blobs in HTML; JA3/JA4 of staging host | UA/feature gate so only the exact target build receives stage-2; single-use, expiring URLs |
Deep Dives
- references/v8-jit-typeconfusion.md — V8 object model, Map/element-kinds, TurboFan/Maglev/Turboshaft speculation bugs; CVE-2024-4947/5274, CVE-2025-2135/5419/10585 patterns. Build
addrof/fakeobjand an in-cage arbitrary R/W via a fake TypedArray. Backed byv8_typer.js,d8_debug.sh. - references/v8-sandbox-escape.md — The V8 heap sandbox (pointer compression, external-pointer & trusted-pointer tables); escaping via raw pointers in Wasm objects (WasmIndirectFunctionTable / Liftoff), Trusted Pointer Table abuse, and pivot to RWX Wasm code. Backed by
sandbox_escape.js. - references/renderer-to-browser-escape.md — Escaping the OS sandbox: Mojo IPC handle-confusion logic bugs (CVE-2025-2783 ForumTroll, CVE-2025-4609 ipcz), GPU-process memory bugs (Dawn/WebGPU, ANGLE CVE-2025-6558), fuzzing Mojo interfaces. Backed by
mojo_fuzz_harness.py. - references/electron-webview-rce.md — Electron/CEF/WebView2 model;
nodeIntegration/contextIsolation/sandboxmatrix, preload-bridge & IPC abuse, deprecatedwebviewTag, ASAR integrity bypass (CVE-2025-55305) and V8 snapshot/fuse tampering, XSS->RCE. Backed byelectron_audit.py. - references/clientside-rce-chains.md — Stitching primitives into a reliable 1-click chain; staged delivery, UA/feature gating, reliability hardening, cross-engine (JSC/WebKit CVE-2025-43529) primitive porting, patch-diffing for n-days. Backed by
chain_server.py.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
