Let Me Unwind That For You: Exceptions to Backward-Edge Protection
Victor Duta, Fabian Freyer, Fabio Pagani, Marius Muench, Cristiano Giuffrida
Abstract
—Backward-edge control-flow hijacking via stack buffer overflow is the holy grail of software exploitation. The ability to directly control critical stack data and the hijacked target makes this exploitation strategy particularly appealing for attackers. As a result, the community has deployed strong backward-edge protections such as shadow stacks or stack canaries, forcing attackers to resort to less ideal e.g., heap-based exploitation strategies. However, such mitigations commonly rely on one key assumption, namely an attacker relying on return address corruption to directly hijack control flow upon function return. In this paper, we present exceptions to this assumption and show attacks based on backward-edge control-flow hijacking without the direct hijacking are possible. Specifically, we demonstrate that stack corruption can cause exception handling to act as a confused deputy and mount backward-edge control-flow hijacking attacks on the attacker’s behalf. This strategy provides overlooked opportunities to divert execution to attacker-controlled catch handlers (a paradigm we term Catch Handler Oriented Programming or CHOP) and craft powerful primitives such as arbitrary code execution or arbitrary memory writes. We find CHOP-style attacks to work across multiple platforms (Linux, Windows, macOS, Android and iOS). To analyze the uncovered attack surface, we survey popular open-source packages and study the applicability of the proposed exploitation techniques. Our analysis shows that suitable exception handling targets are ubiquitous in C++ programs and exploitable exception handlers are common. We conclude by presenting three end-to-end exploits on real-world software and proposing changes to deployed mitigations to address CHOP.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- On Bridging the Gap between Control Flow Integrity and Attestation SchemesMahmoud Ammar, Ahmed Abdelraoof, Silviu VlasceanuUSENIX Security 2024 · 9 citations
- OCFI: Make Function Entry Identification Hard AgainChengbin Pang, Tiantai Zhang, Xuelan Xu, Linzhang Wang et al.ISSTA 2023 · 3 citations
- BreakFAST: Confused Deputy Attack on Infinity Fabric to Break AMD SEV-SNPPhilipp Giersfeld, Benedict Schlüter, Shweta ShindeS&P 2026 · 1 citation
- Manipulative Interference AttacksSamuel Mergendahl, Stephen Fickas, Boyana Norris, Richard SkowyraCCS 2024 · 1 citation
- SoK: Integrity, Attestation, and Auditing of Program ExecutionMahmoud Ammar, Adam Caulfield, Ivan De Oliveira NunesS&P 2025
Builds on8
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 170 citations
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
- Undermining Information Hiding (and What to Do about It)Enes Göktas, Robert Gawlik, Benjamin Kollenda, Elias Athanasopoulos et al.USENIX Security 2016 · 82 citations
Related papers
- Crashing Through Defenses: Exploiting Segfaults and Chaining Around Intel CETMarcos Bajo, Ritvik Goyal, Apostolos Chatzianagnostou, Christian RossowS&P 2026
- µRAI: Securing Embedded Systems with Return Address IntegrityNaif Saleh Almakhdhub, Abraham A. Clements, Saurabh Bagchi, Mathias PayerNDSS 2020
- Await() a Second: Evading Control Flow Integrity by Hijacking C++ CoroutinesMarcos Bajo, Christian RossowUSENIX Security 2025
- Finding Cracks in Shields: On the Security of Control Flow Integrity MechanismsYuan Li, Mingzhe Wang, Chao Zhang, Xingman Chen et al.CCS 2020 · 32 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
