writeups.xyz writeups.xyz / Browser Hacking

Title Vulnerabilities Programs Authors
Exploiting Steam: Usual and Unusual Ways in the CEF Framework
CVE-2024-2887: A Pwn2Own Winning Bug In Google Chrome
Bypassing browser tracking protection for CORS misconfiguration abuse
CVE-2023-5480: Chrome new XSS Vector
“MyFlaw” — Cross Platform 0-Day RCE Vulnerability Discovered in Opera’s Browser
Uncovering a crazy privilege escalation from Chrome extensions
CVE-2022-4908: SOP bypass in Chrome using Navigation API
Shifting boundaries: Exploiting an Integer Overflow in Apple Safari
Discovering Headroll (CVE-2023–0704) in Chromium
Hacking the Nintendo DSi Browser
How Browser’s Save As Feature might lead to Code Execution (CVE-2022–45415)
Google Chrome “SymStealer” Vulnerability: How to Protect Your Files from Being Stolen
Chromium: Same Origin Policy bypass within a single site a.k.a. "Google Roulette"
Jit-Picking: Differential Fuzzing of JavaScript Engines
Safari is hot-linking images to semi-random websites
Guest Blog Post - Memory corruption vulnerabilities in Edge
Step-by-Step Walkthrough of CVE-2022-32792 - WebKit B3ReduceStrength Out-of-Bounds Write
But You Told Me You Were Safe: Attacking The Mozilla Firefox Renderer (Part 1)
A Story of a Bug Found Fuzzing
Extracting Clear-Text Credentials Directly From Chromium’s Memory
CVE-2022-0337 System environment variables leak on Google Chrome, Microsoft Edge and Opera
webOS Revisited - Even More Mistaken Identities
Hacking the Apple Webcam (again)
Exploitation Of CVE-2021-21220 – From Incorrect JIT Behavior To RCE
Play The Opera Please