Skip to content
Loading...
Courses Offensive Security

Browser Exploitation

Apex-level exploit development targeting V8, SpiderMonkey, and JavaScriptCore. JIT compilation abuse, sandbox escapes, and full browser exploit chains from vulnerability to code execution.

This course includes:
  • 14 modules, 131 lessons
  • 27 hands-on labs
  • 14 quizzes
  • Lifetime course access
  • Certificate of completion
  • One certification attempt included
  • Certification is lifetime - never expires
  • 14-day refund guarantee*
* See conditions
Browser Exploitation
$2,999 One-time payment
Enroll Already have an account?
Next start: September 12, 2026
Expert
14 modules
131 lessons
27 labs

About This Course

What You'll Learn

Understand JavaScript engine internals (V8, SpiderMonkey, JSC)
Exploit JIT compilation vulnerabilities for code execution
Develop type confusion and use-after-free exploits in browser contexts
Escape browser sandboxes on Windows, macOS, and Linux
Chain vulnerabilities into full browser exploit chains
Analyze real-world browser CVEs and write proof-of-concept exploits

Course Curriculum

This is a preview of the course content. Register to access all lessons.
Module 1 - Browser Architecture And Attack Surface
10 lessons
Multi-Process Architecture Lesson
Chrome Process Model Lesson
Firefox Process Model Lesson
Safari Process Model Lesson
Attack Surface Mapping Lesson
Threat Model Per Boundary Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 2 - JavaScript Engine Fundamentals
10 lessons
Parsing and Bytecode Generation Lesson
Object Representation and Hidden Classes Lesson
Inline Caches and Type Feedback Lesson
Speculative Optimization and Deoptimization Lesson
Garbage Collection Algorithms Lesson
Type Representation and Tagging Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 3 - V8 Internals And Exploitation
11 lessons
V8 Object Model: Maps and Elements Lesson
TurboFan IR and Optimization Pipeline Lesson
V8 Heap Layout and Pointer Compression Lesson
The V8 Sandbox Lesson
ArrayBuffer and TypedArray Exploitation Lesson
OOB Access and addrof/fakeobj Lesson
V8 CVE Walkthroughs Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 4 - SpiderMonkey Internals And Exploitation
10 lessons
SpiderMonkey Object Model Lesson
WarpMonkey JIT Pipeline Lesson
Nursery and Tenured Heap Lesson
Type Inference Exploitation Lesson
ArrayBuffer Exploitation in SpiderMonkey Lesson
Firefox-Specific Techniques Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 5 - JavaScriptCore Internals And Exploitation
10 lessons
JSC Object Model and Butterflies Lesson
DFG and FTL JIT Tiers Lesson
MarkedSpace and Gigacage Lesson
PAC Integration on Apple Silicon Lesson
JSC Exploit Primitives Lesson
iOS Safari Exploitation Context Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 6 - JIT Compiler Vulnerability Classes
11 lessons
Type Confusion Via Incorrect Speculation Lesson
Bounds Check Elimination Bugs Lesson
Escape Analysis and Redundancy Elimination Lesson
Register Allocation and JIT Spraying Lesson
CVE Walkthroughs Across Engines Lesson
Patch Diffing JIT Fixes Lesson
Cross-Engine Comparison Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 7 - Garbage Collector Exploitation
9 lessons
GC-Triggered Use-After-Free Lesson
GC Rooting Errors Lesson
Concurrent GC Race Conditions Lesson
Nursery Promotion and Weak Reference Bugs Lesson
GC-Based Information Leaks Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 8 - WebAssembly And Beyond JavaScript
9 lessons
Wasm Memory Model Lesson
Wasm JIT Exploitation Lesson
Wasm as Exploitation Primitive Lesson
WebGPU and WebGL Attack Surface Lesson
DOM and Rendering Engine Bugs Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 9 - Renderer Sandbox Architecture
10 lessons
Chrome Site Isolation and Mojo Lesson
Firefox Fission and IPDL Lesson
WebKit Process Model and XPC Lesson
Linux Sandbox: seccomp-BPF and Namespaces Lesson
macOS Sandbox: Seatbelt and App Sandbox Lesson
Windows Sandbox: Win32k and LPAC Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 10 - Sandbox Escape Techniques
10 lessons
IPC Message Confusion Lesson
Mojo Interface Exploitation Lesson
IPDL Exploitation Lesson
XPC Exploitation Lesson
Broker and GPU Process Attacks Lesson
Shared Memory and File-Backed IPC Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 11 - Browser Fuzzing And Vulnerability Discovery
11 lessons
Domato: Grammar-Based DOM Fuzzing Lesson
Fuzzilli: Coverage-Guided JavaScript Engine Fuzzing Lesson
ClusterFuzz and OSS-Fuzz Integration Lesson
Differential JavaScript Engine Testing Lesson
JIT Fuzzing Strategies Lesson
Patch Diffing Browser Commits Lesson
Building Custom Browser Fuzzers Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Module 12 - Full Exploit Chains
10 lessons
Chrome Full Chain Exploitation Lesson
Firefox Full Chain Exploitation Lesson
Safari Full Chain Exploitation Lesson
Mobile Browser Exploit Chains Lesson
Chain Reliability and Weaponization Lesson
The Economics of Browser Exploits Lesson
Practical Exercises Hands-On
Key Takeaways Lesson
Quiz Assessment
Lab Hands-On
Capstone Project
3 lessons
The Target Project
Deliverables Project
Assessment Criteria Project
Certification Preparation
7 lessons
Exam Overview Lesson
Domains and Weightings Lesson
Exam Environment and Rules Lesson
Preparation Strategy Lesson
Registration and Logistics Lesson
After Certification Lesson
Career Leverage Lesson