Browser Vulnerabilities with Proof-of-Concept Exploits in Exploitarium: Complete 2024 Catalog
Exploitarium maintains five functional proof-of-concept exploits targeting browser components in Firefox 152.0.x, Ladybird, and Chromium-based Electron applications.
The Exploitarium repository by bikini aggregates full-stack security research with runnable demonstrations. Each browser vulnerability PoC includes the complete payload—HTML, WebAssembly modules, server scripts, and binary components—needed to reproduce the exploit against a stock browser installation. This catalog covers all browser-related vulnerabilities currently tracked in the repository's main branch.
Firefox 152.0.5: Backup Recovery NSS DLL Load RCE
The first Firefox PoC exploits the browser's profile backup restoration mechanism to achieve native code execution through DLL hijacking.
How the Exploit Works
A malicious page delivered via about:welcome triggers automatic download of a crafted profile backup. When the user attempts to restore this backup, Firefox's NSS (Network Security Services) component loads firefox_calc_payload.dll from the attacker-controlled backup archive. The malicious DLL executes arbitrary native code, launching Calculator as demonstration.
Running the PoC
# Start the local PoC server from the exploit directory
python -B server.py
# Open the printed URL with stock Firefox binary
& "C:\Program Files\Mozilla Firefox\firefox.exe" "http://127.0.0.1:8896/"
Key source files in firefox-152.0.5-backup-nss-rce-poc/:
server.py— HTTP server delivering the payloadexploit.html— Landing page triggering backup downloadfirefox_calc_payload.dll— Malicious DLL executed via NSS load
Firefox 152.0.6: Stock Page Native Calculator via BrowserBridge
This PoC demonstrates a memory-safety primitive in Baseline-JIT escalating to privileged execution without requiring profile manipulation.
Technical Flow
The standalone HTML page triggers a JIT compiler bug to establish a memory safety violation. This primitive bridges into Firefox's BrowserBridge component—a privileged IPC mechanism between content processes and the parent. Through this bridge, the exploit executes a native payload that opens Calculator directly from a fresh browser session.
Exploit Structure
<!-- exploit.html – served from any reachable web server -->
<script type="module">
import "./native_browserbridge.wasm";
// WASM module triggers JIT primitive and bridge hijack
</script>
Critical files in firefox-152.0.6-stock-page-native-calc-poc/:
exploit.html— Entry point with module loadernative_browserbridge.wasm— Compiled WASM triggering the vulnerability- Supporting JavaScript glue for bridge communication
Firefox SmartWindow: Private Browsing URL Exfiltration
Unlike the prior RCE exploits, this vulnerability targets information disclosure through Firefox's AI-assisted SmartWindow feature.
Vulnerability Mechanism
SmartWindow processes page titles from browser history to provide context-aware assistance. When a malicious page writes a crafted title containing private-URL tokens to history, subsequent SmartWindow queries expand these tokens into actual private browsing URLs. The get_page_content fetch then transmits these URLs to attacker-controlled endpoints.
Payload Configuration
{
"expandedPrivateUrl": "https://www.google.com/search?client=firefox-b-1-d&q=Show+me+my+recent+browser+history"
}
The exfiltration chain executes automatically once the poisoned history entry exists and SmartWindow activates. Source implementation in firefox-smartwindow-private-url-exfil-poc/server.py handles the data collection endpoint.
Ladybird: WASM-to-ESM Host Function RCE
The Ladybird browser PoC targets the WebContent process through a WebAssembly host function vulnerability.
Exploit Characteristics
Ladybird implements WebAssembly with JavaScript ESM (ECMAScript Module) integration. The PoC crafts a minimal HTML page loading exploit.wasm, which invokes an ESM host function with improper validation. This achieves native code execution inside the browser process without sandbox escape.
<script type="module">
import "./exploit.wasm";
</script>
Files in ladybird-wasm-esm-host-function-rce-poc/:
README.md— Technical documentationexploit.wasm— Crafted module triggering host function RCE
Discord Activity: Electron/Chromium Renderer RCE
While targeting a desktop application, this PoC fundamentally exploits Chromium renderer vulnerabilities through Electron's architecture.
Attack Surface
Discord's desktop client embeds Chromium via Electron. The PoC delivers a malicious page as a Discord Activity—a legitimate feature for interactive experiences. Once loaded in the Chromium renderer, the page hijacks the Electron IPC bridge to execute native commands, launching Calculator on Windows.
Deployment Steps
# Serve the malicious activity
python -m http.server 8000
# In Discord client, add activity pointing to http://localhost:8000/
The exploit does not require Discord vulnerabilities per se; it abuses the trust boundary between Chromium renderer and Electron main process. Source in discord-activity-stock-client-rce-poc/exploit.html implements the IPC bridge hijack.
Repository Structure and Navigation
All browser vulnerability PoCs follow consistent organization:
| Vulnerability | Directory | Primary Language |
|---|---|---|
| Firefox 152.0.5 NSS RCE | firefox-152.0.5-backup-nss-rce-poc/ |
Python, HTML, C (DLL) |
| Firefox 152.0.6 Native Calc | firefox-152.0.6-stock-page-native-calc-poc/ |
HTML, WASM, JavaScript |
| Firefox SmartWindow Exfil | firefox-smartwindow-private-url-exfil-poc/ |
Python, JavaScript |
| Ladybird WASM RCE | ladybird-wasm-esm-host-function-rce-poc/ |
WASM, HTML |
| Discord Electron RCE | discord-activity-stock-client-rce-poc/ |
HTML, JavaScript |
Each directory contains standalone execution instructions in its README.md per the bikini/exploitarium repository standards.
Security Research Implications
These browser vulnerability proof-of-concepts demonstrate several critical attack patterns:
- Trusted UI abuse:
about:welcomeand profile restoration workflows execute with user-equivalent trust - JIT compiler exploitation: Modern JavaScript engines remain high-value targets for memory safety violations
- AI feature side channels: SmartWindow's history analysis creates unintended information disclosure vectors
- WASM host function surface: Emerging browsers like Ladybird introduce new attack surfaces in module bindings
- Renderer-to-main privilege escalation: Electron applications multiply Chromium vulnerability impact through IPC bridges
Summary
- Firefox 152.0.5 backup NSS DLL load — RCE via profile restoration and NSS hijacking
- Firefox 152.0.6 stock page native calc — JIT primitive to BrowserBridge privilege escalation
- Firefox SmartWindow private URL exfil — AI feature information disclosure through history poisoning
- Ladybird WASM ESM host function RCE — WebAssembly host function vulnerability in alternative browser
- Discord Activity Electron RCE — Chromium renderer exploitation via Electron IPC bridge
Each PoC in bikini/exploitarium includes complete, runnable source code verifying the vulnerability against stock browser installations.
Frequently Asked Questions
What versions of Firefox are vulnerable to these exploits?
The backup NSS DLL load targets Firefox 152.0.5 on Windows 11, while the stock page native calc PoC targets Firefox 152.0.6. The SmartWindow private URL exfiltration affects Firefox 152.0.2 and later versions. These represent point-in-time vulnerabilities addressed through Mozilla's security update process; the PoCs serve as historical reference implementations.
Does Exploitarium contain Chrome or Chromium-specific browser vulnerabilities?
The repository does not include standalone Chrome or Chromium browser PoCs. The Discord Activity RCE indirectly exploits Chromium through Electron's embedded renderer, but no dedicated Chrome browser vulnerabilities are currently tracked. Repository searches for "chrome" and "chromium" return only the Electron-related implementation and documentation references.
Are these browser vulnerability PoCs suitable for security testing or red team exercises?
Each PoC is designed for controlled research environments with explicit authorization. The exploits achieve native code execution against stock browser configurations, making them suitable for validating endpoint protection, browser sandbox hardening, and user awareness training—provided all legal and policy requirements for authorized testing are satisfied.
What distinguishes the Ladybird vulnerability from the Firefox exploits?
The Ladybird PoC targets an alternative browser engine implementing WebAssembly with ESM host functions, a modern architectural pattern distinct from Firefox's Spidermonkey runtime. This vulnerability demonstrates that emerging browsers inherit familiar WebAssembly risks despite clean-slate implementations, specifically around host function validation boundaries between WASM modules and native code.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →