{"enrichment":{"faq":[{"a":"browser-exploitation is a skill for weaponizing client-side browser vulnerabilities into full host compromise by chaining JS-engine bugs through multiple sandbox layers. It covers V8 and JavaScriptCore exploitation, heap-sandbox escape techniques, OS-sandbox bypass via Mojo IPC and GPU processes, and Electron/webview misconfigurations, along with scripts, references, and OPSEC guidance for assembling 1-click drive-by RCE delivery.","q":"What is browser-exploitation and what does it cover?"},{"a":"browser-exploitation teaches V8 JIT type confusion as a foundational technique for building complete exploit chains from JS engine bugs to RCE. Type confusion vulnerabilities in the JIT compiler allow attackers to corrupt object types in memory, enabling arbitrary read/write primitives that form the basis for escaping the V8 heap sandbox and progressing toward OS-level compromise.","q":"How do V8 JIT type confusion exploits work in browser-exploitation?"},{"a":"browser-exploitation covers multiple sandbox escape vectors: heap sandbox escape using WASM pointers and addrof/fakeobj primitives, renderer-to-browser privilege escalation, and OS sandbox bypass through Mojo IPC abuse and GPU process vulnerabilities. These techniques chain together to move from renderer process compromise toward full system RCE.","q":"What browser sandbox escape techniques does browser-exploitation teach?"},{"a":"browser-exploitation addresses Electron RCE by teaching IPC abuse and preload misconfiguration exploitation, including contextIsolation bypass and ASAR integrity tampering. These methods allow attackers to escape the renderer sandbox and achieve code execution in the main process, which typically runs with elevated privileges.","q":"How can browser-exploitation help exploit Electron RCE via IPC abuse?"},{"a":"browser-exploitation includes OPSEC-aware client-side payload development with detection evasion techniques. This covers building 1-click drive-by RCE chains that minimize forensic artifacts, evade endpoint detection, and maintain stealth during delivery and execution across modern browser architectures.","q":"What OPSEC guidance does browser-exploitation provide for payloads?"},{"a":"Yes, browser-exploitation teaches fuzzing and exploitation of Mojo broker and GPU process vulnerabilities, including WebGPU GPU process use-after-free, ANGLE/Dawn GPU driver bugs, and Mojo IPC fuzzing harnesses. These represent the final sandbox layers between renderer and OS kernel.","q":"Does browser-exploitation cover GPU process and Mojo vulnerabilities?"}],"shadow_tags":["memory-corruption-primitives","multi-stage-exploitation","sandbox-boundary-breaking","jit-engine-targeting","ipc-logic-bugs","opsec-telemetry-evasion","embedded-browser-apps","gpu-subsystem-attacks","cross-browser-portability","staged-delivery-chains"],"summary_rewrite":"Weaponize client-side browser vulnerabilities into full host compromise by chaining JS-engine bugs through multiple sandbox layers. This skill covers V8 and JavaScriptCore exploitation, heap-sandbox escape techniques, OS-sandbox bypass via Mojo IPC and GPU processes, and Electron/webview misconfigurations. Includes scripts, references, and OPSEC guidance for assembling 1-click drive-by RCE delivery."},"files":[{"bytes":9844,"path":"skills/browser-exploitation/SKILL.md","sha256":"11ab5553711f1fec224647d36f4368f9d335c77c5f27453dcfacadd2f16f3ae1","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/browser-exploitation/5ddf4a32/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/browser-exploitation","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/browser-exploitation","md":"https://skillfed.io/hypnguyen1209/offensive-claude/browser-exploitation.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"browser-exploitation","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"yaklang/hack-skills/browser-exploitation-v8"},{"id":"yaklang/hack-skills/sandbox-escape-techniques"},{"id":"hypnguyen1209/offensive-claude/exploit-development"},{"id":"fathah/hermes-desktop/electron-pro"},{"id":"jwynia/agent-skills/electron-best-practices"},{"id":"electron/electron/electron-node-upgrade"},{"id":"pedronauck/skills/electron-dev"},{"id":"Gentleman-Programming/Gentleman-Skills/electron"},{"id":"modu-ai/moai-adk/moai-framework-electron"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"browser-exploitation"},"version":"5ddf4a32"}
