Fuzzing JavaScript Engines with a Graph-based IR
Haoran Xu, Zhiyuan Jiang, Yongjun Wang, Shuhui Fan, Shenglin Xu, Peidai Xie, Shaojing Fu, Mathias Payer
Abstract
Mutation-based fuzzing effectively discovers defects in JS engines. High-quality mutations are key for the performance of mutationbased fuzzers. The choice of the underlying representation (e.g., a sequence of tokens, an abstract syntax tree, or an intermediate representation) defines the possible mutation space and subsequently influences the design of mutation operators. Current program representations in JS engine fuzzers center around abstract syntax trees and customized bytecode-level intermediate languages. However, existing efforts struggle to generate semantically valid and meaningful mutations, limiting the discovery of defects in JS engines. Our proposed graph-based intermediate representation, FlowIR, directly represents the JS control flow and data flow as the mutation target. FlowIR is essential for the implementation of powerful semantic mutation. It supports mutation operators at the data flow and control flow level, thereby expanding the granularity of mutation operators. Experimental results show that our method is more effective in discovering new bugs. Our prototype, FuzzFlow, outperforms state-of-the-art fuzzers in generating valid test cases and exploring code coverage. In our evaluation, we detected 37 new defects in thoroughly tested mainstream JS engines. CCS Concepts • Security and privacy → Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6094826b-3b9a-4cf3-82b8-47c12bbcdbfbCited by top-tier papers3
- Validating JIT Compilers via Compilation Space ExplorationCong Li, Yanyan Jiang, Chang Xu, Zhendong SuSOSP 2023 · 22 citations
- Extraction and Mutation at a High Level: Template-Based Fuzzing for JavaScript EnginesWai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Yiteng Peng et al.OOPSLA 2025 · 4 citations
- CrossFit: Demystifying VM Callback Bugs in InterpretersChibin Zhang, Qiang Liu, Mathias PayerFSE 2026
Builds on18
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
- LAVA: Large-Scale Automated Vulnerability AdditionBrendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek et al.S&P 2016 · 354 citations
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 178 citations
- Fuzzing JavaScript Engines with Aspect-preserving MutationSoyeon Park, Wen Xu, Insu Yun, Daehee Jang et al.S&P 2020 · 126 citations
Related papers
- FUZZILLI: Fuzzing for JavaScript JIT Compiler VulnerabilitiesSamuel Groß, Simon Koch, Lukas Bernhard, Thorsten Holz et al.NDSS 2023
- SoFi: Reflection-Augmented Fuzzing for JavaScript EnginesXiaoyu He, Xiaofei Xie, Yuekang Li, Jianwen Sun et al.CCS 2021 · 34 citations
- Token-Level FuzzingChristopher Salls, Chani Jindal, Jake Corina, Christopher Kruegel et al.USENIX Security 2021
- FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT CompilerJunjie Wang, Zhiyi Zhang, Shuang Liu, Xiaoning Du et al.USENIX Security 2023
- FREEDOM: Engineering a State-of-the-Art DOM FuzzerWen Xu, Soyeon Park, Taesoo KimCCS 2020 · 25 citations
