Empirical Security Analysis of Software-based Fault Isolation through Controlled Fault Injection
Nils Bars, Lukas Bernhard, Moritz Schloegel, Thorsten Holz
Abstract
We use browsers daily to access all sorts of information. Because browsers routinely process scripts, media, and executable code from unknown sources, they form a critical security boundary between users and adversaries. A common attack vector is JavaScript, which powers complex web interactions but exposes a large attack surface due to the sheer complexity of modern JavaScript engines. To mitigate these threats, modern engines increasingly adopt software-based fault isolation (SFI). A prominent example is Google's V8 heap sandbox, which represents the most widely deployed SFI mechanism, protecting billions of users across all Chromium-based browsers and countless applications built on Node.js and Electron. The heap sandbox splits the address space into two parts: one part containing trusted, security-sensitive metadata, and a sandboxed heap containing memory accessible to untrusted code. On a technical level, the sandbox enforces isolation by removing raw pointers and using translation tables to resolve references to trusted objects. Consequently, an attacker cannot corrupt trusted data even with full control of the sandboxed data, unless there is a bug in how code handles data from the sandboxed heap. Despite their widespread use, such SFI mechanisms have seen surprisingly little security testing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b62d2617-31c2-4ee7-830e-2d8762aa2d00Cited by top-tier papers1
Ask how each one uses itBuilds on15
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- LibAFL: A Framework to Build Modular and Reusable FuzzersAndrea Fioraldi, Dominik Christian Maier, Dongjia Zhang, Davide BalzarottiCCS 2022 · 71 citations
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard et al.S&P 2024 · 69 citations
- JIT-Picking: Differential Fuzzing of JavaScript EnginesLukas Bernhard, Tobias Scharnowski, Moritz Schloegel, Tim Blazytko et al.CCS 2022 · 42 citations
Related papers
- Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation ImplementationsJan Drescher, David Klein, Martin JohnsNDSS 2026
- TANTRUM: Breaking the Heap Sandbox in JavaScript Engines via Protection Domain FuzzingSeunghyun Lee, David BrumleyCCS 2026
- Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFIShravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek et al.ASPLOS 2023 · 27 citations
- Isolation without taxation: near-zero-cost transitions for WebAssembly and SFIMatthew Kolosick, Shravan Narayan, Evan Johnson, Conrad Watt et al.POPL 2022 · 14 citations
- Lightweight Fault Isolation: Practical, Efficient, and Secure Software SandboxingZachary YedidiaASPLOS 2024 · 17 citations
