logo

Reverse engineering Claude's CVE-2026-2796 exploit

ID: 11e94069-05d6-4a98-b34f-ba2e484e50b6

STIX ID: report--11e94069-05d6-4a98-b34f-ba2e484e50b6

Threat Score

60/100

Uploaded: 2026-08-03

Published Date: 2026-03-06

Last Modified Date: 2026-08-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
...
...
Frontier Red Team reverse-engineered an exploit that Claude (Opus 4.6) authored for CVE-2026-2796, a Firefox WebAssembly JIT miscompilation: the bug allowed a call.bind wrapper to be unwrapped at instantiation, leading to type confusion and an unchecked path that enabled addrof/fakeobj primitives, WasmGC-based arbitrary 64-bit reads/writes, and ultimately code execution in a stripped js shell; the issue is now patched and the exploit relied on a testing environment with some mitigations disabled, but the case highlights improving LLM capabilities for writing exploits.