Breaking Chrome's V8: Type confusion, WASM JIT-Spraying and Heap Sandbox Evasion

No ratings

Presented at Zer0Con 2025 by

Chrome's V8 engine remains a prime target for attackers, with type confusion vulnerabilities driving some of the most impactful exploits in recent years. In this talk, we'll explore the modern landscape of V8 exploitation, focusing on how recent CVEs, bypass strengthened defenses such as the V8 heap sandbox. We'll examine the evolution of Chrome's JIT pipeline, the role of speculative optimizations in introducing type confusion, and how techniques like WASM JIT-spraying have adapted to new mitigations. Through real-world case studies and live debugging demos, attendees will gain practical insights into breaking V8 in 2024, from exploitation chains requiring multiple bugs to advanced evasion tactics targeting Chrome's latest security model.