Browser JavaScript Exploits

The cluster focuses on discussions about JavaScript-based exploits in modern web browsers like Chrome and Firefox, including vulnerabilities in JS engines, sandbox escapes, mitigations, and real-world zero-days.

📉 Falling 0.5x Security
3,500
Comments
19
Years Active
5
Top Authors
#2417
Topic ID

Activity Over Time

2008
7
2009
40
2010
96
2011
122
2012
152
2013
213
2014
146
2015
219
2016
276
2017
211
2018
340
2019
283
2020
233
2021
261
2022
261
2023
229
2024
183
2025
215
2026
13

Keywords

AFAIK www.kb e.g CSS JS HTML5 RIDL WebKit cert.org RCE browser exploits exploit firefox js attack javascript chrome mitigations browsers

Sample Comments

vvillena Nov 18, 2018 View on HN

There are exploits written in Javascript that run on a browser.

nqzero Jan 19, 2016 View on HN

citation for your exploits claim ? you've worded it in an awkward manner that makes it sound like a red herringspecifically, are there javascript-only (or js+css+html only) exploits in recent chrome or firefox ?

kazinator Nov 2, 2019 View on HN

Imagine if someone discovers a flaw in any library that your web browser uses, or the browser itself or is JS engine ... oh no!

iamflimflam1 Aug 3, 2023 View on HN

I guess you've never heard of browser exploits?

edflsafoiewq Jun 19, 2021 View on HN

Didn't browsers implement their own mitigations? Or were those only for some vulns?

blackflame7000 Jan 3, 2018 View on HN

I might be wrong, but shouldn't browser makers be able to prevent executing scripts from exploiting the low level memory manipulation this requires?

Expurple Aug 17, 2023 View on HN

Aren't some of these speculation vulnerabilities exploitable from Javascript? This makes everyday web browsing "require security"

acchow Jan 21, 2014 View on HN

Exploits can escape your browser sandbox.

heinrich5991 Jul 8, 2024 View on HN

AFAIK most of modern web browser vulnerabilities come from JavaScript engines.

sabret00the Sep 25, 2012 View on HN

What browsers have this exploit been tested with?