Preliminary research
Reverse engineering Claude's CVE-2026-2796 exploit
AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from March through September. Unranked, incomplete, not community-vetted, and subject to change.
Develops a Firefox JavaScript/Wasm type-confusion bug from an unchecked optimized call.bind wrapper into WasmGC read/write primitives and code execution. The write-up also records the model-assisted exploit-development process and the manual validation used to turn a crashing test into a reliable chain.
Record
- Researcher
- Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng and Daniel Freeman
- Published by
- Anthropic
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng and Daniel Freeman, first published at the original source. Preserved copies are kept so the citation survives its host.