SymWeb: Feedback-Driven Context Exploration and Context-Aware Symbolic Execution for Browser-Embedded WebAssembly Vulnerability Detection
Yuanpeng Wang, Yeqi Fu, Zhineng Zhong, Zhenkai Liang, Ding Li, Yao Guo, Xiangqun Chen
Abstract
Browser-deployed WebAssembly (Wasm) modules often inherit memory-safety bugs from C and C++-style code, yet exploiting, and even reaching, these bugs in the Web threat model is fundamentally context-dependent. JavaScript (JS) controls the exported-call schedule and constructs the Wasm entry state, including arguments, globals, and linear-memory layouts, from attacker-influenced web inputs. This makes both Wasm-only analysis, which assumes static initial states, and prior browser-based testing such as Wemby ineffective. Wemby generates a fixed, Wasm-agnostic context pool and then only mutates Wasm parameters, which limits its ability to systematically reach deeper, Wasm-relevant contexts and gated behaviors. We present SymWeb, a feedback-driven closed-loop system that links external inputs to browser-reachable JS-induced Wasm contexts and then to context-aware Wasm symbolic execution. SymWeb couples an Feedback-driven Context Generator with an Context-Aware Wasm Symbolic Executor. The Feedback-driven Context Generator performs binary rewriting for ASan-like checks and observability, collects contexts in the browser, and uses Influence-guided Mutation to steer web inputs. The symbolic executor clusters and symbolizes contexts, performs coverage-guided symbolic execution under reachable entry states, and returns actionable constraints to steer the next online round. We evaluate SymWeb on 30 real-world Wasm-enabled websites. Under our Web threat model, SymWeb verifies 17 exploitable vulnerabilities and achieves 72.8% average Wasm basic-block coverage. Compared to the browser-based baseline Wemby, SymWeb finds 8 more verified vulnerabilities and improves coverage by 19.9 percentage points. Compared to the Wasm-only baseline WASEM, SymWeb finds 14 more verified vulnerabilities and improves coverage by 40.4 percentage points. Overall, these results show that closing the loop between browser-reachable context generation and context-aware Wasm analysis substantially improves both vulnerability-finding effectiveness and exploration depth in real Web environments.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Wemby's Web: Hunting for Memory Corruption in WebAssemblyOussama Draissi, Tobias Cloosters, David Klein, Michael Rodler et al.ISSTA 2025 · 1 citation
- LWDIFF: an LLM-Assisted Differential Testing Framework for Webassembly RuntimesShiyao Zhou, Jincheng Wang, He Ye, Hao Zhou et al.ICSE 2025 · 2 citations
- Everything Old is New Again: Binary Security of WebAssemblyDaniel Lehmann, Johannes Kinder, Michael PradelUSENIX Security 2020
- Waltzz: WebAssembly Runtime Fuzzing with Stack-Invariant TransformationLingming Zhang, Binbin Zhao, Jiacheng Xu, Peiyu Liu et al.USENIX Security 2025
- EOSAFE: Security Analysis of EOSIO Smart ContractsNingyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu et al.USENIX Security 2021 · 69 citations
