{"enrichment":{"faq":[{"a":"browser-exploitation-v8 covers advanced V8 and Chrome exploitation methods, including JIT type confusion, incorrect bounds elimination, and pointer compression bypass. The skill focuses on building addrof and fakeobj primitives from type confusion vulnerabilities, corrupting ArrayBuffer backing stores, and leveraging WASM RWX pages for renderer RCE and sandbox escape.","q":"What V8 exploitation techniques does browser-exploitation-v8 teach?"},{"a":"browser-exploitation-v8 teaches how to construct arbitrary read/write primitives from type confusion vulnerabilities in V8's JIT compiler. These primitives form the foundation for memory corruption attacks, enabling you to read and write arbitrary memory locations needed for further exploitation of the browser sandbox.","q":"How can I build arbitrary read/write primitives using browser-exploitation-v8?"},{"a":"browser-exploitation-v8 covers pointer compression bypass techniques that allow attackers to circumvent V8's sandbox architecture. Understanding pointer compression mechanisms and their weaknesses is critical for developing reliable exploits that can escape the renderer process and achieve full browser compromise.","q":"What is pointer compression V8 sandbox bypass in browser-exploitation-v8?"},{"a":"browser-exploitation-v8 demonstrates how to achieve renderer RCE by corrupting ArrayBuffer backing stores through type confusion and memory corruption primitives. By manipulating ArrayBuffer objects, attackers can gain arbitrary read/write access, which can then be leveraged to execute shellcode and compromise the renderer process.","q":"How does browser-exploitation-v8 explain renderer RCE via ArrayBuffer?"},{"a":"browser-exploitation-v8 teaches how to exploit WASM memory corruption to create RWX pages for shellcode execution in Chrome. By combining V8 memory corruption primitives with WebAssembly capabilities, attackers can bypass code execution restrictions and achieve full renderer compromise.","q":"What WebAssembly exploitation methods are covered in browser-exploitation-v8?"},{"a":"browser-exploitation-v8 includes coverage of Chrome IPC and Mojo exploitation for full browser process compromise. This represents advanced attack surface beyond the renderer, enabling attackers to escalate from sandbox escape to complete browser takeover through inter-process communication vulnerabilities.","q":"Does browser-exploitation-v8 cover Chrome IPC and Mojo exploitation?"}],"shadow_tags":["jit-optimization-bugs","memory-corruption-primitives","sandbox-containment-bypass","code-execution-gadgets","heap-layout-manipulation","browser-process-compromise","pointer-tagging-schemes","type-system-confusion","renderer-process-exploitation","ipc-attack-surface"],"summary_rewrite":"This skill covers advanced V8 and Chrome exploitation methods, including JIT type confusion, incorrect bounds elimination, and pointer compression bypass. Learn to build addrof and fakeobj primitives, corrupt ArrayBuffer backing stores, and leverage WASM RWX pages for renderer RCE and sandbox escape."},"files":[{"bytes":12459,"path":"skills/browser-exploitation-v8/SKILL.md","sha256":"47a589e8a3dd9540ac8fe95f75105cc53a5e2c6f5500689f5c97677c36a73538","url":"https://skillfed.io/files/yaklang/hack-skills/browser-exploitation-v8/6e7231a7/SKILL.md"}],"id":"yaklang/hack-skills/browser-exploitation-v8","links":{"html":"https://skillfed.io/yaklang/hack-skills/browser-exploitation-v8","md":"https://skillfed.io/yaklang/hack-skills/browser-exploitation-v8.md","repo":"https://github.com/yaklang/hack-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":196,"language":"CSS","last_updated":"2026-06-16","license":"MIT","name":"browser-exploitation-v8","publisher":"yaklang","stars":1480},"relations":{"similar":[{"id":"hypnguyen1209/offensive-claude/browser-exploitation"},{"id":"hypnguyen1209/offensive-claude/exploit-development"},{"id":"ljagiello/ctf-skills/ctf-pwn"},{"id":"yaklang/hack-skills/binary-protection-bypass"},{"id":"hypnguyen1209/offensive-claude/shellcode-dev"},{"id":"hypnguyen1209/offensive-claude/edr-evasion"},{"id":"mcollina/skills/nodejs-core"},{"id":"hypnguyen1209/offensive-claude/malware-analysis"},{"id":"vercel/next.js/v8-jit"},{"id":"yaklang/hack-skills/sandbox-escape-techniques"}]},"slug":{"owner":"yaklang","repo":"hack-skills","skill":"browser-exploitation-v8"},"version":"6e7231a7"}
