# Browser Vulnerabilities with Proof-of-Concept Exploits in Exploitarium: Complete 2024 Catalog

> Explore browser vulnerabilities with proof-of-concept exploits in bikini/exploitarium. Discover exploits for Firefox, Ladybird, and Electron apps in our 2024 catalog.

- Repository: [bikini/exploitarium](https://github.com/bikini/exploitarium)
- Tags: api-reference
- Published: 2026-09-06

---

**Exploitarium maintains five functional proof-of-concept exploits targeting browser components in Firefox 152.0.x, Ladybird, and Chromium-based Electron applications.**

The Exploitarium repository by bikini aggregates full-stack security research with runnable demonstrations. Each browser vulnerability PoC includes the complete payload—HTML, WebAssembly modules, server scripts, and binary components—needed to reproduce the exploit against a stock browser installation. This catalog covers all browser-related vulnerabilities currently tracked in the repository's main branch.

## Firefox 152.0.5: Backup Recovery NSS DLL Load RCE

The first Firefox PoC exploits the browser's profile backup restoration mechanism to achieve native code execution through DLL hijacking.

### How the Exploit Works

A malicious page delivered via `about:welcome` triggers automatic download of a crafted profile backup. When the user attempts to restore this backup, Firefox's NSS (Network Security Services) component loads `firefox_calc_payload.dll` from the attacker-controlled backup archive. The malicious DLL executes arbitrary native code, launching Calculator as demonstration.

### Running the PoC

```powershell

# Start the local PoC server from the exploit directory

python -B server.py

# Open the printed URL with stock Firefox binary

& "C:\Program Files\Mozilla Firefox\firefox.exe" "http://127.0.0.1:8896/"

```

Key source files in `firefox-152.0.5-backup-nss-rce-poc/`:
- [`server.py`](https://github.com/bikini/exploitarium/blob/main/server.py) — HTTP server delivering the payload
- [`exploit.html`](https://github.com/bikini/exploitarium/blob/main/exploit.html) — Landing page triggering backup download
- `firefox_calc_payload.dll` — Malicious DLL executed via NSS load

## Firefox 152.0.6: Stock Page Native Calculator via BrowserBridge

This PoC demonstrates a **memory-safety primitive in Baseline-JIT** escalating to privileged execution without requiring profile manipulation.

### Technical Flow

The standalone HTML page triggers a JIT compiler bug to establish a memory safety violation. This primitive bridges into Firefox's **BrowserBridge** component—a privileged IPC mechanism between content processes and the parent. Through this bridge, the exploit executes a native payload that opens Calculator directly from a fresh browser session.

### Exploit Structure

```html
<!-- exploit.html – served from any reachable web server -->
<script type="module">
  import "./native_browserbridge.wasm";
  // WASM module triggers JIT primitive and bridge hijack
</script>

```

Critical files in `firefox-152.0.6-stock-page-native-calc-poc/`:
- [`exploit.html`](https://github.com/bikini/exploitarium/blob/main/exploit.html) — Entry point with module loader
- `native_browserbridge.wasm` — Compiled WASM triggering the vulnerability
- Supporting JavaScript glue for bridge communication

## Firefox SmartWindow: Private Browsing URL Exfiltration

Unlike the prior RCE exploits, this vulnerability targets **information disclosure** through Firefox's AI-assisted SmartWindow feature.

### Vulnerability Mechanism

SmartWindow processes page titles from browser history to provide context-aware assistance. When a malicious page writes a crafted title containing private-URL tokens to history, subsequent SmartWindow queries expand these tokens into actual private browsing URLs. The `get_page_content` fetch then transmits these URLs to attacker-controlled endpoints.

### Payload Configuration

```json
{
  "expandedPrivateUrl": "https://www.google.com/search?client=firefox-b-1-d&q=Show+me+my+recent+browser+history"
}

```

The exfiltration chain executes automatically once the poisoned history entry exists and SmartWindow activates. Source implementation in [`firefox-smartwindow-private-url-exfil-poc/server.py`](https://github.com/bikini/exploitarium/blob/main/firefox-smartwindow-private-url-exfil-poc/server.py) handles the data collection endpoint.

## Ladybird: WASM-to-ESM Host Function RCE

The Ladybird browser PoC targets the **WebContent process** through a WebAssembly host function vulnerability.

### Exploit Characteristics

Ladybird implements WebAssembly with JavaScript ESM (ECMAScript Module) integration. The PoC crafts a minimal HTML page loading `exploit.wasm`, which invokes an ESM host function with improper validation. This achieves **native code execution inside the browser process** without sandbox escape.

```html
<script type="module">
  import "./exploit.wasm";
</script>

```

Files in `ladybird-wasm-esm-host-function-rce-poc/`:
- [`README.md`](https://github.com/bikini/exploitarium/blob/main/README.md) — Technical documentation
- `exploit.wasm` — Crafted module triggering host function RCE

## Discord Activity: Electron/Chromium Renderer RCE

While targeting a desktop application, this PoC fundamentally exploits **Chromium renderer vulnerabilities** through Electron's architecture.

### Attack Surface

Discord's desktop client embeds Chromium via Electron. The PoC delivers a malicious page as a Discord Activity—a legitimate feature for interactive experiences. Once loaded in the Chromium renderer, the page hijacks the **Electron IPC bridge** to execute native commands, launching Calculator on Windows.

### Deployment Steps

```powershell

# Serve the malicious activity

python -m http.server 8000

# In Discord client, add activity pointing to http://localhost:8000/

```

The exploit does not require Discord vulnerabilities per se; it abuses the **trust boundary between Chromium renderer and Electron main process**. Source in [`discord-activity-stock-client-rce-poc/exploit.html`](https://github.com/bikini/exploitarium/blob/main/discord-activity-stock-client-rce-poc/exploit.html) implements the IPC bridge hijack.

## Repository Structure and Navigation

All browser vulnerability PoCs follow consistent organization:

| Vulnerability | Directory | Primary Language |
|-------------|-----------|------------------|
| Firefox 152.0.5 NSS RCE | `firefox-152.0.5-backup-nss-rce-poc/` | Python, HTML, C (DLL) |
| Firefox 152.0.6 Native Calc | `firefox-152.0.6-stock-page-native-calc-poc/` | HTML, WASM, JavaScript |
| Firefox SmartWindow Exfil | `firefox-smartwindow-private-url-exfil-poc/` | Python, JavaScript |
| Ladybird WASM RCE | `ladybird-wasm-esm-host-function-rce-poc/` | WASM, HTML |
| Discord Electron RCE | `discord-activity-stock-client-rce-poc/` | HTML, JavaScript |

Each directory contains standalone execution instructions in its [`README.md`](https://github.com/bikini/exploitarium/blob/main/README.md) per the bikini/exploitarium repository standards.

## Security Research Implications

These browser vulnerability proof-of-concepts demonstrate several critical attack patterns:

- **Trusted UI abuse**: `about:welcome` and profile restoration workflows execute with user-equivalent trust
- **JIT compiler exploitation**: Modern JavaScript engines remain high-value targets for memory safety violations
- **AI feature side channels**: SmartWindow's history analysis creates unintended information disclosure vectors
- **WASM host function surface**: Emerging browsers like Ladybird introduce new attack surfaces in module bindings
- **Renderer-to-main privilege escalation**: Electron applications multiply Chromium vulnerability impact through IPC bridges

## Summary

- **Firefox 152.0.5 backup NSS DLL load** — RCE via profile restoration and NSS hijacking
- **Firefox 152.0.6 stock page native calc** — JIT primitive to BrowserBridge privilege escalation
- **Firefox SmartWindow private URL exfil** — AI feature information disclosure through history poisoning
- **Ladybird WASM ESM host function RCE** — WebAssembly host function vulnerability in alternative browser
- **Discord Activity Electron RCE** — Chromium renderer exploitation via Electron IPC bridge

Each PoC in bikini/exploitarium includes complete, runnable source code verifying the vulnerability against stock browser installations.

## Frequently Asked Questions

### What versions of Firefox are vulnerable to these exploits?

The backup NSS DLL load targets **Firefox 152.0.5 on Windows 11**, while the stock page native calc PoC targets **Firefox 152.0.6**. The SmartWindow private URL exfiltration affects **Firefox 152.0.2 and later versions**. These represent point-in-time vulnerabilities addressed through Mozilla's security update process; the PoCs serve as historical reference implementations.

### Does Exploitarium contain Chrome or Chromium-specific browser vulnerabilities?

The repository does not include standalone Chrome or Chromium browser PoCs. The **Discord Activity RCE** indirectly exploits Chromium through Electron's embedded renderer, but no dedicated Chrome browser vulnerabilities are currently tracked. Repository searches for "chrome" and "chromium" return only the Electron-related implementation and documentation references.

### Are these browser vulnerability PoCs suitable for security testing or red team exercises?

Each PoC is designed for **controlled research environments** with explicit authorization. The exploits achieve native code execution against stock browser configurations, making them suitable for validating endpoint protection, browser sandbox hardening, and user awareness training—provided all legal and policy requirements for authorized testing are satisfied.

### What distinguishes the Ladybird vulnerability from the Firefox exploits?

The Ladybird PoC targets an **alternative browser engine** implementing WebAssembly with ESM host functions, a modern architectural pattern distinct from Firefox's Spidermonkey runtime. This vulnerability demonstrates that emerging browsers inherit familiar WebAssembly risks despite clean-slate implementations, specifically around host function validation boundaries between WASM modules and native code.