logo

Researcher Releases Android Exploit In Webkit Browser Engine

ID: af81dac3-554e-5e31-8591-69af935702db

STIX ID: report--af81dac3-554e-5e31-8591-69af935702db

Feed Name: Darknet

Threat Score
78/100

Date Published: 2010-11-07

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from major browsers including Chrome/Edge/Brave (App-Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI) and Firefox (NSS). It uses headless Chromium + Early Bird APC DLL injection to access the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is presented as a red-team tool but represents a high-risk capability for real-world adversaries seeking lateral movement and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.