"The Web/Local" Boundary Is Fuzzy: A Security Study of Chrome's Process-based Sandboxing
Yaoqi Jia, Zheng Leong Chua, Hong Hu, Shuo Chen, Prateek Saxena, Zhenkai Liang
Abstract
Process-based isolation, suggested by several research prototypes, is a cornerstone of modern browser security architectures. Google Chrome is the first commercial browser that adopts this architecture. Unlike several research prototypes, Chrome's process-based design does not isolate different web origins, but primarily promises to protect "the local system" from "the web". However, as billions of users now use web-based cloud services (e.g., Dropbox and Google Drive), which are integrated into the local system, the premise that browsers can effectively isolate the web from the local system has become questionable. In this paper, we argue that, if the process-based isolation disregards the same-origin policy as one of its goals, then its promise of maintaining the "web/local system (local)" separation is doubtful. Specifically, we show that existing memory vulnerabilities in Chrome's renderer can be used as a stepping-stone to drop executables/scripts in the local file system, install unwanted applications and misuse system sensors. These attacks are purely data-oriented and do not alter any control flow or import foreign code. Thus, such attacks bypass binary-level protection mechanisms, including ASLR and in-memory partitioning. Finally, we discuss various full defenses and present a possible way to mitigate the attacks presented.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 105 citations
- Leaky Images: Targeted Privacy Attacks in the WebCristian-Alexandru Staicu, Michael PradelUSENIX Security 2019 · 21 citations
- Timing-Based Browsing Privacy Vulnerabilities Via Site IsolationZihao Jin, Ziqiao Kong, Shuo Chen, Haixin DuanS&P 2022 · 2 citations
- Not All Data are Created Equal: Data and Pointer Prioritization for Scalable Protection Against Data-Oriented AttacksSalman Ahmed, Hans Liljestrand, Hani Jamjoom, Matthew Hicks et al.USENIX Security 2023
Builds on2
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris et al.NDSS 2016 · 141 citations
Related papers
- State of Browser Process-Isolation: The Same-Site WeaknessFabian Kilger, Hannah Fischer, Adrian Staeves, Robin Marchart et al.S&P 2026
- Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation ImplementationsJan Drescher, David Klein, Martin JohnsNDSS 2026
- Spook.js: Attacking Chrome Strict Site Isolation via Speculative ExecutionAyush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel et al.S&P 2022 · 32 citations
- Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and ExtensionsSuyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin et al.S&P 2026
- Extending a Hand to Attackers: Browser Privilege Escalation Attacks via ExtensionsYoung Min Kim, Byoungyoung LeeUSENIX Security 2023
