<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Javascript-Engine — PoC Archive</title><link>https://poc.intelseclab.com/tags/javascript-engine/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 19 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/javascript-engine/index.xml" rel="self" type="application/rss+xml"/><item><title>V8 Array Iterator Maglev Type Confusion — addrof/fakeobj Primitives (CVE-2026-14431)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-19_cve-2026-14431-v8-array-iterator-maglev-type-confusion/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-19_cve-2026-14431-v8-array-iterator-maglev-type-confusion/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-14431. Status: PoC — real, working sandboxed read/write primitives (addrof/fakeobj); no sandbox-escape/RCE chain published (author states this is still in progress). Affects: V8 JavaScript engine (Google Chrome and other Chromium-based browsers). Tags: v8, javascript-engine, chromium, maglev, type-confusion, array-iterator, cwe-843, sandboxed-read-write, memory-corruption.</description><category>binary</category><category>High</category><category>v8</category><category>javascript-engine</category><category>chromium</category><category>maglev</category><category>type-confusion</category><category>array-iterator</category><category>cwe-843</category><category>sandboxed-read-write</category><category>memory-corruption</category></item><item><title>V8 JavaScript Engine Exploit — "Longinus" Kit (CVE-2026-6307)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-6307-longinus-v8-exploit-kit/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-6307-longinus-v8-exploit-kit/</guid><description>Critical severity — binary · CVE-2026-6307. Status: Weaponized. Affects: V8 JavaScript engine (Chromium-based browsers). Tags: v8, javascript-engine, browser-exploit, memory-corruption, yara, exploit-kit.</description><category>binary</category><category>Critical</category><category>v8</category><category>javascript-engine</category><category>browser-exploit</category><category>memory-corruption</category><category>yara</category><category>exploit-kit</category></item><item><title>Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_ladybird-wasm-esm-host-function-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_ladybird-wasm-esm-host-function-rce/</guid><description>Critical severity — web · None assigned as of 2026-07-03. Status: Weaponized. Affects: Ladybird web browser (WebContent process, LibWeb / LibWasm). Tags: ladybird, browser, webassembly, wasm-gc, use-after-free, memory-corruption, rce, javascript-engine, sandbox-escape.</description><category>web</category><category>Critical</category><category>ladybird</category><category>browser</category><category>webassembly</category><category>wasm-gc</category><category>use-after-free</category><category>memory-corruption</category><category>rce</category><category>javascript-engine</category><category>sandbox-escape</category></item></channel></rss>