USENIX Security2026Top-tier venue
BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface
Mingi Jung, Donggyu Kim, Mijung Kim, Seongil Wi
Abstract
Modern web ecosystems rely on security policy headers, such as Content Security Policy (CSP) and the SameSite cookie attribute, for client-side defenses. Because browsers enforce these headers, browser bugs in policy enforcement directly undermine these defenses. While recent studies have attempted to find such bugs, they largely overlook bugs triggered by user interactions on the browser user interface (BUI).
In this paper, we propose BUIZZ, the first testing framework that identifies policy enforcement bugs triggered by BUI-level user interactions. BUIZZ first collects a comprehensive set of interactions by referencing browser manuals, right-click context menus, and known browser bugs. It then executes each interaction and their combinations on the test pages via OS-level simulation. Instead of cross-browser differential testing, BUIZZ leverages a pre/post-interaction oracle that checks for enforcement inconsistencies before and after applying interactions, enabling bug detection within a single browser. We demonstrate the efficacy of BUIZZ by finding 35 security bugs and three functional bugs across six browsers, including Chrome and Firefox. Our reports have led to fixes for 14 security bugs, resulting in seven CVEs and $14,700 in bug bounties.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 15e50d2e-b25b-405b-83c9-3b453fb1efeeBuilds on39
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 178 citations
- IMF: Inferred Model-based FuzzerHyungSeok Han, Sang Kil ChaCCS 2017 · 139 citations
- Fuzzing JavaScript Engines with Aspect-preserving MutationSoyeon Park, Wen Xu, Insu Yun, Daehee Jang et al.S&P 2020 · 126 citations
Related papers
- DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential TestingSeongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock et al.NDSS 2023
- Head(er)s Up! Detecting Security Header Inconsistencies in BrowsersJannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben StockCCS 2025
- Web Platform Threats: Automated Detection of Web Security Issues With WPTPedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara et al.USENIX Security 2024 · 6 citations
- A Bug's Life: Analyzing the Lifecycle and Mitigation Process of Content Security Policy BugsGertjan Franken, Tom van Goethem, Lieven Desmet, Wouter JoosenUSENIX Security 2023
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes et al.USENIX Security 2020
