CorbFuzz: Checking Browser Security Policies with Fuzzing
Chaofan Shou, Ismet Burak Kadron, Qi Su, Tevfik Bultan
Abstract
Browsers use security policies to block malicious behaviors. Cross-Origin Read Blocking (CORB) is a browser security policy for preventing side-channel attacks such as Spectre. We propose a web browser security policy fuzzer called CorbFuzz for checking CORB and similar policies. In implementing a security policy, the browser only has access to HTTP requests and responses, and takes policy actions based solely on those interactions. In checking the browser security policies, CorbFuzz uses a policy oracle that tracks the web application behavior and infers the desired policy action based on the web application state. By comparing the policy oracle with the browser behavior, CorbFuzz detects weaknesses in browser security policies. CorbFuzz checks the web browser policy by fuzzing a set of web applications where the state-related queries are symbolically evaluated for increased coverage and automation. CorbFuzz collects type information from database queries and branch conditions in order to prevent the generation of inconsistent data values during fuzzing. We evaluated CorbFuzz on CORB implementations of Chromium and Webkit, and Opaque Response Blocking (ORB) policy implementation of Firefox using web applications collected from GitHub. We found three classes of weaknesses in Chromium’s implementation of CORB.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bcdeecb3-8e29-4cb4-a11d-66d1c93e1a1bCited by top-tier papers8
- ItyFuzz: Snapshot-Based Fuzzer for Smart ContractChaofan Shou, Shangyin Tan, Koushik SenISSTA 2023 · 76 citations
- Enhancing Coverage-Guided Fuzzing via Phantom ProgramMingyuan Wu, Kunqiu Chen, Qi Luo, Jiahong Xiang et al.FSE 2023 · 7 citations
- Tacoma: Enhanced Browser Fuzzing with Fine-Grained Semantic AlignmentJiashui Wang, Peng Qian, Xilin Huang, Xinlei Ying et al.ISSTA 2024 · 3 citations
- DarthShader: Fuzzing WebGPU Shader Translators & CompilersLukas Bernhard, Nico Schiller, Moritz Schloegel, Nils Bars et al.CCS 2024 · 3 citations
- Keyword Extraction From Specification Documents for Planning Security MechanismsJeffy Jahfar Poozhithara, Hazeline U. Asuncion, Brent LagesseICSE 2023 · 1 citation
Builds on10
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 105 citations
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes et al.CCS 2017 · 74 citations
Related papers
- Spook.js: Attacking Chrome Strict Site Isolation via Speculative ExecutionAyush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel et al.S&P 2022 · 32 citations
- Robust Website Fingerprinting Through the Cache Occupancy ChannelAnatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser et al.USENIX Security 2019 · 159 citations
- Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation ImplementationsJan Drescher, David Klein, Martin JohnsNDSS 2026
- TriChord: Extension-Oriented Browser Fuzzing for ChromiumHuinian Yang, Daoyuan Wu, Qingyu Li, Yiming LiuCCS 2026
- BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User InterfaceMingi Jung, Donggyu Kim, Mijung Kim, Seongil WiUSENIX Security 2026
