Browser-Exploit-Dojo is a curated archive of browser and JavaScript engine exploitation CTF challenges, organized by bug class, exploitation primitive, final technique, difficulty, and solve count. The goal is to document practical browser exploitation techniques through hands-on CTF challenges, with an initial focus on V8 and JavaScript engine exploitation.
The archive covers techniques such as type confusion, out-of-bounds access, JIT compiler bugs, WebAssembly exploitation, memory corruption, and exploit primitives leading to arbitrary read/write and code execution.
“Dojo” means a training place; this repository is intended as a practice-oriented archive for learning browser exploitation through CTF challenges.
Each challenge directory contains the original distribution files when available, exploit code, and a technical writeup.
Challenges are organized by year, and the top-level Challenge List serves as an index to each challenge directory.
For technique-based navigation, see Techniques Index.
Note: Year folders are based on the actual event date, not necessarily the year shown in the CTF name.
Browser-Exploit-Dojo(道場)は、Browser / JavaScript Engine Exploit の CTF 問題を、Bug・Primitive・Final Technique・Difficulty・Solve 数ごとに整理する技術アーカイブです。まずは V8 を中心に、実践的なブラウザエンジンの exploit 技術を体系的にまとめることを目指します。
Type Confusion、Out-of-Bounds Access、JIT Compiler の脆弱性、WebAssembly Exploitation、Memory Corruption、Arbitrary Read/Write、Code Execution など、ブラウザエンジンの exploit に関する技術を扱います。
「道場」は練習・鍛錬の場という意味です。本リポジトリは、CTF 問題を通じて Browser Exploit を学び、技術を比較・復習するための実践的なアーカイブです。
各問題のディレクトリには、入手可能な配布ファイル、exploit code、技術解説をまとめます。
各問題は開催年別に整理し、トップページの Challenge List から各問題へ移動できる構成にします。
技術別に探したい場合は Techniques Index を参照してください。
Note: 年度別フォルダは、CTF 名に含まれる年ではなく、実際の開催年を基準にします。
This repository is intended for CTF learning, security research, and isolated local testing environments only. Do not run exploits against browsers, systems, or services without proper authorization.
Browser exploits may cause crashes, memory corruption, or arbitrary code execution. Use isolated environments and the exact challenge versions whenever possible.
本リポジトリは、CTF 学習、セキュリティ研究、および隔離されたローカル検証環境向けです。適切な許可なく、ブラウザ、システム、サービスに対して exploit を実行しないでください。
Browser exploit は、クラッシュ、メモリ破壊、任意コード実行などを引き起こす可能性があります。可能な限り、対象の challenge と同一のバージョンを隔離環境で使用してください。
Difficulty is based on exploit complexity, required engine knowledge, exploitation primitives, and solve count. Ratings are subjective and intended as practical learning references.
Difficulty は exploit の複雑さ、必要なエンジン内部の知識、利用する Primitive、Solve 数をもとに主観的に分類しています。学習や技術比較のための目安です。
| CTF | Challenge | Status | Difficulty (Solves) | Bug | Primitive | Final Technique |
|---|---|---|---|---|---|---|
| M*CTF 2025 Quals | Baby Browser | solved | Easy (7) | array length increment | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| RSTCON 2025 CTF | Optimization | solved | Easy (?) | array length decrement | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| PatriotCTF 2024 | babyxss | solved / writeup | Easy (?) | unchecked array length modification | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| SAS CTF 2024 Quals | Ubercaged | solved / writeup | Easy (?) | unchecked OOB access in Array.prototype.readAt / writeAt | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| Null CTF 2025 | reloc8 | solved / writeup | Easy-Medium (10) | inconsistent ToNumber() coercion enables bounds-check bypass | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| Infobahn CTF 2025 | The Butterfly effect | solved / writeup | Easy-Medium (14) | custom ArrayMagic builtin OOB access | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| Securinets CTF Quals 2025 | Sukunahikona | solved / writeup | Easy-Medium (14) | reentrant ToNumber() array length corruption | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| UTCTF 2025 | E-Corp Part 2 | solved / writeup | Easy-Medium (31) | invalid ElementsKind transition | addrof / fakeobj / AAR / AAW | wasm jump table hijack + shellcode execution |
| TFC CTF 2025 | SPECUL8 | writeup | Medium (4) | TurboFan type inference bug in StringMultiply | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| UMDCTF 2025 | literally-1985 | solved / writeup | Medium (10) | TurboFan JIT miscompilation (out-of-bounds access) | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| CrewCTF 2025 | Wherechall | writeup | Medium-High (9) | wasm GC array.fill bounds check bypass | addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
| DownUnderCTF 2025 | entangled revenge | writeup | Medium-High (11) | V8 entangled object handling | out-of-bounds access | flag object corruption |
| FCSC 2024 | Holy Cow | writeup | Medium-High (?) | map corruption via exposed the_hole value | addrof / AAR / AAW | wasm code overwrite + shellcode execution |
| bi0sCTF 2024 | ezv8 revenge | writeup | Medium-High (10) | TurboFan map inference bug in Reflect.construct | OOB Read/Write, addrof / AAR / AAW | wasm jump table hijack + shellcode execution |
The archive aims to cover the following techniques as challenges are added:
-
JavaScript engine internals
-
V8 reverse engineering
-
Type confusion
-
Out-of-bounds read/write
-
JIT compiler misoptimization
-
TurboFan optimization bugs
-
JavaScript runtime exploitation
-
Object layout and memory representation
-
Heap corruption
-
Arbitrary read/write primitives
-
Pointer and object reference manipulation
-
Garbage collector interactions
-
WebAssembly exploitation
-
WebAssembly type confusion and validation bugs
-
JIT code generation and executable memory
-
Shellcode generation and execution
-
Sandboxed execution and security boundaries
-
Browser sandbox escape, where applicable
-
Engine-specific exploitation techniques
-
Exploit reliability and mitigation bypasses
The actual scope depends on the available challenges and their target engines. Techniques will be added and refined as the archive grows.
Challenges may require a specific browser or JavaScript engine build, compilation options, runtime flags, or a custom execution environment.
For V8 challenges, the d8 shell is commonly used when provided or built from the corresponding source version. The required runtime flags and build instructions should be documented in each challenge directory.
Example:
./d8 exp01.js
For WebAssembly-related challenges, the exact engine version and required Wasm features may be essential for reproducing the behavior.
Always refer to the individual challenge README for the appropriate build and execution instructions.
Exploit code in this repository is primarily intended for local CTF environments and controlled testing.
Unless explicitly stated otherwise, exploits authored or modified in this repository are tested against the available local challenge environment. Their behavior is not guaranteed on other engine versions, build configurations, operating systems, or browser environments.
JavaScript engine internals, JIT optimization behavior, object layouts, pointer representations, and available runtime features can change between versions. Some exploits may require specific flags, compilation settings, memory layouts, or environmental conditions.
本リポジトリの exploit code は、主にローカルの CTF 環境および管理された検証環境での動作確認を目的としています。
特に明記していない限り、作成・修正した exploit は、入手可能なローカル challenge 環境を中心に検証しています。異なるエンジンバージョン、ビルド設定、OS、ブラウザ環境での動作は保証していません。
JavaScript Engine の内部実装、JIT 最適化、オブジェクトのメモリ配置、ポインタ表現、利用可能なランタイム機能はバージョンによって変化します。特定のフラグ、ビルド設定、メモリ配置、実行環境が必要な場合があります。
Large distribution files, such as browser binaries, debug builds, source archives, and VM images, may be omitted from this repository when they are too large or impractical to maintain directly.
In such cases, only the minimum files required for analysis are included. External download links, source revisions, build instructions, or notes about the original distribution are provided when available.
サイズが大きい、またはリポジトリでの管理が困難なブラウザバイナリ、デバッグビルド、ソースアーカイブ、VM イメージなどは、直接含めない場合があります。
その場合は、解析に必要な最小限のファイルを配置し、可能であれば外部ダウンロードリンク、ソースのリビジョン、ビルド手順、元配布ファイルに関するメモを記載します。
-
README.md— metadata, challenge summary, bug analysis, and exploitation overview -
distribution/— original challenge files, binaries, and relevant resources -
exploit/— exploit source code and helper scripts, if available -
writeup/— technical analysis, reproduction notes, and external references
Original challenge files are preserved for archival and analysis purposes whenever possible. Some files may contain intentionally vulnerable software and should only be executed in isolated environments.
-
README.md— メタデータ、問題概要、脆弱性の分析、exploit の概要 -
distribution/— 元の配布ファイル、バイナリ、関連リソース -
exploit/— exploit のソースコードや補助スクリプト -
writeup/— 技術解析、再現手順、外部参考資料
可能な限り、元の challenge ファイルをアーカイブおよび解析目的で保存します。意図的に脆弱性を含むソフトウェアもあるため、必ず隔離された環境で実行してください。
Browser and JavaScript engine exploitation resources will be added as the archive grows.
本リポジトリの成長に合わせて、Browser / JavaScript Engine Exploit に関する参考資料を追加します。
I would like to express my sincere gratitude to all CTF organizers and challenge authors who created these excellent browser exploitation challenges.
Many of the techniques, exploit strategies, and implementation details in this repository are learned from public writeups, author writeups, source code, and shared research. I deeply appreciate everyone who documents their findings and makes technical knowledge available to the community.
This repository is intended as a personal learning archive and technical index. All credit for the original challenges belongs to the respective CTF organizers and challenge authors. All credit for referenced writeups and research belongs to their original authors.
素晴らしい Browser Exploit 問題を作成してくださった CTF 運営・問題作者の皆様に深く感謝します。
本リポジトリに含まれる技術、exploit 方針、実装上の知見は、公開 writeup、author writeup、ソースコード、各種研究資料から多くを学んだものです。技術的な知見を記録し、コミュニティに共有してくださった皆様にも心より感謝します。
本リポジトリは、個人の学習記録および技術索引として整理するものです。各 CTF 問題の権利とクレジットは、それぞれの CTF 運営・問題作者に帰属します。参照した writeup や研究資料のクレジットは、それぞれの原著者に帰属します。