Towards Better Semantics Exploration for Browser Fuzzing
Chijin Zhou, Quan Zhang, Lihua Guo, Mingzhe Wang, Yu Jiang, Qing Liao, Zhiyong Wu, Shanshan Li, Bin Gu
Abstract
Web browsers exhibit rich semantics that enable a plethora of web-based functionalities. However, these intricate semantics present significant challenges for the implementation and testing of browsers. For example, fuzzing, a widely adopted testing technique, typically relies on handwritten context-free grammars (CFGs) for automatically generating inputs. However, these CFGs fall short in adequately modeling the complex semantics of browsers, resulting in generated inputs that cover only a portion of the semantics and are prone to semantic errors. In this paper, we present SaGe, an automated method that enhances browser fuzzing through the use of production-context sensitive grammars (PCSGs) incorporating semantic information. Our approach begins by extracting a rudimentary CFG from W3C standards and iteratively enhancing it to create a PCSG. The resulting PCSG enables our fuzzer to generate inputs that explore a broader range of browser semantics with a higher proportion of semantically-correct inputs. To evaluate the efficacy of SaGe, we conducted 24-hour fuzzing campaigns on mainstream browsers, including Chrome, Safari, and Firefox. Our approach demonstrated better performance compared to existing browser fuzzers, with a 6.03%-277.80% improvement in edge coverage, a 3.56%-161.71% boost in semantic correctness rate, twice the number of bugs discovered. Moreover, we identified 62 bugs across the three browsers, with 40 confirmed and 10 assigned CVEs.
CCS Concepts: • Software and its engineering → Software testing and debugging; • Security and privacy → Browser security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bdf90d7f-6bdc-43d8-bc8d-ce82b05ed6f8Cited by top-tier papers10
- PolyJuice: Detecting Mis-compilation Bugs in Tensor Compilers with Equality Saturation Based RewritingChijin Zhou, Bingzhou Qian, Gwihwan Go, Quan Zhang et al.OOPSLA 2024 · 7 citations
- Tacoma: Enhanced Browser Fuzzing with Fine-Grained Semantic AlignmentJiashui Wang, Peng Qian, Xilin Huang, Xinlei Ying et al.ISSTA 2024 · 3 citations
- DarthShader: Fuzzing WebGPU Shader Translators & CompilersLukas Bernhard, Nico Schiller, Moritz Schloegel, Nils Bars et al.CCS 2024 · 3 citations
- Janus: Detecting Rendering Bugs in Web Browsers via Visual Delta ConsistencyChijin Zhou, Quan Zhang, Bingzhou Qian, Yu JiangICSE 2025 · 2 citations
- Towards More Complete Constraints for Deep Learning Library Testing via Complementary Set Guided RefinementGwihwan Go, Chijin Zhou, Quan Zhang, Xiazijian Zou et al.ISSTA 2024 · 2 citations
Builds on27
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 178 citations
- Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingStefan Nagy, Matthew HicksS&P 2019 · 156 citations
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
Related papers
- Beyond the Surface: Towards Feature-Driven Fuzzing on the Chrome BrowserChaoyuan Peng, Muhui Jiang, Yajin Zhou, Lei WuISSTA 2026
- Minerva: browser API fuzzing with dynamic mod-ref analysisChijin Zhou, Quan Zhang, Mingzhe Wang, Lihua Guo et al.FSE 2022 · 20 citations
- FREEDOM: Engineering a State-of-the-Art DOM FuzzerWen Xu, Soyeon Park, Taesoo KimCCS 2020 · 25 citations
- FuzzOrigin: Detecting UXSS vulnerabilities in Browsers through Origin FuzzingSunwoo Kim, Young Min Kim, Jaewon Hur, Suhwan Song et al.USENIX Security 2022
- SoFi: Reflection-Augmented Fuzzing for JavaScript EnginesXiaoyu He, Xiaofei Xie, Yuekang Li, Jianwen Sun et al.CCS 2021 · 34 citations
