Finding and Preventing Bugs in JavaScript Bindings
Fraser Brown, Shravan Narayan, Riad S. Wahby, Dawson R. Engler, Ranjit Jhala, Deian Stefan
Abstract
JavaScript, like many high-level languages, relies on runtime systems written in low-level C and C++. For example, the Node.js runtime system gives JavaScript code access to the underlying filesystem, networking, and I/O by implementing utility functions in C++. Since C++'s type system, memory model, and execution model differ significantly from JavaScript's, JavaScript code must call these runtime functions via intermediate binding layer code that translates type, state, and failure between the two languages. Unfortunately, binding code is both hard to avoid and hard to get right. This paper describes several types of exploitable errors that binding code creates, and develops both a suite of easily-to-build static checkers to detect such errors and a backwards-compatible, lowoverhead API to prevent them. We show that binding flaws are a serious security problem by using our checkers to craft 81 proof-ofconcept exploits for security flaws in the binding layers of the Node.js and Chrome, runtime systems that support hundreds of millions of users. As one practical measure of binding bug severity, we were awarded $6,000 in bounties for just two Chrome bug reports. Violation type Possible consequence Crash-safety DOS attacks, including poison-pill attacks [46]; breaking language-level security abstractions, including [42, 43, 95, 110], by introducing a new covert channel. Type-safety Above + type confusion attacks which, for example, can be used to carry out remote code execution attacks. Memory-safety Above + memory disclosure and memory corruption attacks which, for example, can be used to leak TLS keys [29] or turn off the same-origin policy [83]. [Constructor(DOMString[] blobParts)] interface Blob readonly attribute unsigned long size; readonly attribute DOMString contentType; Blob slice(optional unsigned long start, optional unsigned long end); ;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 157ff47a-156e-4587-8b33-1ce13639c4d2Cited by top-tier papers31
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 178 citations
- Detecting Node.js prototype pollution vulnerabilities via object lookup analysisSong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoFSE 2021 · 49 citations
- Abusing Hidden Properties to Attack the Node.js EcosystemFeng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang et al.USENIX Security 2021 · 35 citations
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller et al.ICSE 2020 · 34 citations
Builds on1
Related papers
- Favocado: Fuzzing the Binding Code of JavaScript Engines Using Semantically Correct Test CasesSung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest et al.NDSS 2021
- Bilingual Problems: Studying the Security Risks Incurred by Native Extensions in Scripting LanguagesCristian-Alexandru Staicu, Sazzadur Rahaman, Ágnes Kiss, Michael BackesUSENIX Security 2023
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 91 citations
- Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its EcosystemAbdullah AlHamdan, Cristian-Alexandru StaicuNDSS 2025
- Best of Both Worlds: Effective Foreign Bridge Identification in V8 Embedders for Security AnalysisGeorgios Alexopoulos, Thodoris Sotiropoulos, Zhendong Su, Dimitris MitropoulosS&P 2026 · 1 citation
