4719 | I discovered a browser bug |
Browser hacking |
Mozilla
Microsoft |
Jake Archibald (@jaffathecake) |
Bug Bounty | 2018-06-20 | 2023-06-13 |
4529 | Brave Browser Script Blocker Bypass Vulnerability |
Browser hacking |
Brave Software |
Xiaoyin Liu |
Bug Bounty | 2018-10-13 | 2023-06-13 |
4478 | Spoof All Domains Containing %27d%27 in Apple Products [CVE-2018-4277] |
Browser hacking |
Apple |
Tencent%27s Xuanwu Lab |
Bug Bounty | 2018-11-13 | 2023-06-13 |
4218 | Same-Origin Policy: From birth until today |
SOP bypass
Browser hacking
CSRF
CORS |
Mozilla
Google (Chrome)
Opera |
Alex Nikolova (@AaylaSecura1138) |
Bug Bounty | 2019-04-04 | 2023-06-13 |
4064 | Another Download Protection Bypass in Google Chrome – BIN files in Mac OS |
Browser hacking |
Google |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2019-07-02 | 2023-06-13 |
3834 | Authenticated CORS with Access-Control-Allow-Origin: * |
Caching issue
Browser hacking |
Google (Chromium) |
BitK (@BitK_) |
Bug Bounty | 2019-11-15 | 2023-06-13 |
3807 | Site Isolation bypass via Chrome extension |
Site Isolation bypass
Browser hacking |
Google |
Anthony Weems |
Bug Bounty | 2019-11-27 | 2023-06-13 |
3773 | Javascript Anti Debugging - Abusing SourceMappingURL |
Browser hacking |
Google (Chromium) |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2019-12-17 | 2023-06-13 |
3328 | Issue 1040755: Security: Another "universal" XSS via copy&paste |
Universal XSS
Browser hacking |
Google (Chromium) |
Michał Bentkowski (@SecurityMB) |
Bug Bounty | 2020-07-06 | 2023-06-13 |
3192 | Stealing local files using Safari Web Share API |
Browser hacking |
Apple |
Pawel Wylecial (@h0wlu) |
Bug Bounty | 2020-08-24 | 2023-06-13 |
3156 | Res-block: Extension Resources Block Attack on Chrome’s Incognito Mode |
Browser hacking |
Google |
Piyush Raj (@0x48piraj) |
Bug Bounty | 2020-09-16 | 2023-06-13 |
2906 | Guest Blog Post: Leaking silhouettes of cross-origin images |
Side-channel information leakage
Browser hacking |
Mozilla
Google (Chrome) |
Aleksejs Popovs (@aleksejspopovs) |
Bug Bounty | 2021-01-11 | 2023-06-13 |
2841 | CVE-2020-9759 - Getting root on webOS |
Local Privilege Escalation
Browser hacking |
LG |
Andreas Lindh (@addelindh) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2732 | Bypassing Chrome%27s URL restrictions |
Browser hacking
URL validation bypass |
Google (Chrome) |
Jeffrey Bencteux (@jeffbencteux) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2649 | ELECTRIC CHROME - CVE-2020-6418 on Tesla Model 3 |
RCE
Browser hacking |
Tesla
Google |
Chris Williams (@HawaiiFive0day) |
Bug Bounty | 2021-04-12 | 2023-06-13 |
2648 | You Talking To Me? |
RCE
Browser hacking |
Google |
Li JianTao (@cursered) |
Bug Bounty | 2021-04-12 | 2023-06-13 |
2524 | Bypassing restricted port protection in WebKit |
Browser hacking |
Apple |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-05-26 | 2023-06-13 |
2514 | AppCache%27s forgotten tales |
Browser hacking |
Google (Chrome) |
Luan Herrera (@lbherrera_) |
Bug Bounty | 2021-05-31 | 2023-06-13 |
2395 | Guest Blog Post - Attacking the DevTools |
Browser hacking |
Microsoft |
David Erceg (@david_erceg) |
Bug Bounty | 2021-07-21 | 2023-06-13 |
2320 | A Bug%27s Life: CVE-2021-21225 |
Browser hacking |
Google |
Brendon Tiszka (@btiszka) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2249 | Anti-crawler Burp Suite RCE |
RCE
Browser hacking |
PortSwigger |
Wfox |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2238 | Spook.js: Attacking Google Chrome%27s Strict Site Isolation via Speculative Execution and Type Confusion |
Browser hacking
Side-channel attack
Site Isolation bypass |
Google |
Ayush Agarwal |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2095 | Bypass Chrome Ad-Heavy detection mechanism |
Browser hacking |
Google (Chrome) |
0x0021h (@0x0021h) |
Bug Bounty | 2021-11-09 | 2023-06-13 |
2047 | SSD Advisory – Chrome Ad Heavy Bypass (via history.back()) |
Browser hacking |
Google (Chrome) |
Alesandro Ortiz (@AlesandroOrtizR) |
Bug Bounty | 2021-11-26 | 2023-06-13 |
2042 | Play The Opera Please |
Browser hacking |
Opera |
Dhiraj (@RandomDhiraj) |
Bug Bounty | 2021-11-29 | 2023-06-13 |