Lune

USENIX Security2026Top-tier venue

BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface

Mingi Jung, Donggyu Kim, Mijung Kim, Seongil Wi

2026Year

Abstract

Modern web ecosystems rely on security policy headers, such as Content Security Policy (CSP) and the SameSite cookie attribute, for client-side defenses. Because browsers enforce these headers, browser bugs in policy enforcement directly undermine these defenses. While recent studies have attempted to find such bugs, they largely overlook bugs triggered by user interactions on the browser user interface (BUI).

In this paper, we propose BUIZZ, the first testing framework that identifies policy enforcement bugs triggered by BUI-level user interactions. BUIZZ first collects a comprehensive set of interactions by referencing browser manuals, right-click context menus, and known browser bugs. It then executes each interaction and their combinations on the test pages via OS-level simulation. Instead of cross-browser differential testing, BUIZZ leverages a pre/post-interaction oracle that checks for enforcement inconsistencies before and after applying interactions, enabling bug detection within a single browser. We demonstrate the efficacy of BUIZZ by finding 35 security bugs and three functional bugs across six browsers, including Chrome and Firefox. Our reports have led to fixes for 14 security bugs, resulting in seven CVEs and $14,700 in bug bounties.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 15e50d2e-b25b-405b-83c9-3b453fb1efee

Builds on39

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines