browser-exploitation-v8
Browser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities including JIT type confusion, incorrect bounds elimination, and V8 sandbox bypass to achieve renderer RCE and sandbox escape in Chrome/Chromium.
Security Assessment
About browser-exploitation-v8
A security-testing playbook for exploiting JavaScript-engine vulnerabilities in Google's V8 (Chrome/Chromium). It maps the V8 compilation pipeline — source parsed to an AST, interpreted as Ignition bytecode, then progressively optimized through Sparkplug, Maglev, and the TurboFan optimizing JIT, with deoptimization back to bytecode when speculation fails. Foundational internals are documented too: tagged pointers (SMIs and heap objects), pointer compression that addresses objects via a 32-bit offset from a cage base inside a 4GB region, Maps (hidden classes), elements kinds, the write barrier, and the Orinoco garbage collector.
The bulk of the material catalogs common bug classes and the primitives used to weaponize them. Bug classes include JIT type confusion, incorrect bounds-check elimination, prototype-chain confusion, TurboFan reduction and typer bugs, SharedArrayBuffer race conditions, and off-by-one errors in builtins. From a memory-corruption bug it builds the classic addrof and fakeobj primitives (by confusing object-element and double-element arrays), escalates to arbitrary read/write through a corrupted Float64Array or ArrayBuffer backing store, and covers out-of-bounds access via confused array bounds and WASM RWX pages.
Use it when researching or reproducing renderer RCE and sandbox-escape chains in a controlled, authorized setting. It explains how to force JIT optimization (calling a function many times, or the %OptimizeFunctionOnNextCall intrinsic in d8) and how the V8 sandbox and pointer compression constrain exploitation, since backing-store pointers stay within the cage and a separate sandbox escape is needed for full process memory access. Related routing points to sandbox-escape-techniques, heap-exploitation, stack-overflow-and-rop, and binary-protection-bypass, with a deeper V8_EXPLOITATION_PATTERNS.md reference.
FAQ
What V8 bug classes does the playbook cover?
JIT type confusion, incorrect bounds-check elimination, prototype-chain confusion, TurboFan reduction and typer bugs, SharedArrayBuffer race conditions, and off-by-one errors in built-in functions.
What are the core exploitation primitives it describes?
addrof (leak an object's address) and fakeobj (fabricate an object reference), built by confusing object-element and double-element arrays, then combined into arbitrary read/write through a corrupted Float64Array or ArrayBuffer backing store.
How does the V8 sandbox and pointer compression affect exploitation?
Since V8 8.0 objects are addressed by a 32-bit offset from a cage base within a 4GB region, and ArrayBuffer backing stores are sandbox pointers, so obtaining full process memory access requires a separate sandbox escape.
How do you force a function to be JIT-optimized for testing?
Call it many times (for example 100000 iterations) to trigger TurboFan, or in the d8 shell use the %OptimizeFunctionOnNextCall intrinsic before calling it.
What related skills does it reference?
sandbox-escape-techniques (IPC/Mojo renderer escape), heap-exploitation, stack-overflow-and-rop, and binary-protection-bypass, plus a V8_EXPLOITATION_PATTERNS.md advanced reference for detailed templates.
Install browser-exploitation-v8
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
yaklang/hack-skills