Beyond the Surface: Towards Feature-Driven Fuzzing on the Chrome Browser
Chaoyuan Peng, Muhui Jiang, Yajin Zhou, Lei Wu
Abstract
The Chrome browser constitutes a complex software system responsible for processing and rendering diverse web content. Despite extensive testing and security measures implemented by the vendor and the community, the inherent complexity of this system makes the complete elimination of vulnerabilities practically infeasible. Existing DOM and API fuzzing techniques inadequately address the expanded attack surface introduced by Chrome features and extensions, resulting in a substantial number of elusive vulnerabilities remaining undetected. This paper presents Feazzer, an efficient feature-driven Chrome browser fuzzing framework designed to detect elusive vulnerabilities introduced by Chrome features. Our approach leverages hybrid programs comprising HTML and Chrome extensions with systematically clustered feature options to explore deep browser states in Chrome that existing fuzzers fail to reach. We introduce a message-guided fuzzing mechanism that reduces feature conflicts and enhances the semantic quality of generated test cases. Our comprehensive evaluation across multiple Chrome versions demonstrates that Feazzer achieves up to 231.1% improvement in code coverage compared to state-of-the-art fuzzers. Feazzer has discovered 39 previously unknown bugs in Chrome, with 6 assigned CVEs and acknowledgment of over $55,000 in bug bounties from the vendor. Notably, 2 bugs are rated as critical and 27 as high severity, demonstrating the effectiveness of Feazzer in discovering impactful bugs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Tacoma: Enhanced Browser Fuzzing with Fine-Grained Semantic AlignmentJiashui Wang, Peng Qian, Xilin Huang, Xinlei Ying et al.ISSTA 2024 · 3 citations
- GLeeFuzz: Fuzzing WebGL Through Error Message Guided MutationHui Peng, Zhihao Yao, Ardalan Amiri Sani, Dave Tian et al.USENIX Security 2023
- FREEDOM: Engineering a State-of-the-Art DOM FuzzerWen Xu, Soyeon Park, Taesoo KimCCS 2020 · 25 citations
- Minerva: browser API fuzzing with dynamic mod-ref analysisChijin Zhou, Quan Zhang, Mingzhe Wang, Lihua Guo et al.FSE 2022 · 20 citations
- Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java EcosystemSergej Dechand, Tobias Wienand, Fabian Meumertzheim, Peter Samarin et al.S&P 2026 · 2 citations
