JIT-Picking: Differential Fuzzing of JavaScript Engines
Lukas Bernhard, Tobias Scharnowski, Moritz Schloegel, Tim Blazytko, Thorsten Holz
摘要
Modern JavaScript engines that power websites and even full applications on the Web are driven by the need for an increasingly fast and snappy user experience. These engines use several complex and potentially error-prone mechanisms to optimize their performance. Unsurprisingly, the inevitable complexity results in a huge attack surface and various types of software vulnerabilities. On the defender's side, fuzz testing has proven to be an invaluable tool for uncovering different kinds of memory safety violations. Although it is difficult to test interpreters and JIT compilers in an automated way, recent proposals for input generation based on grammars or target-specific intermediate representations helped uncovering many software faults. However, subtle logic bugs and miscomputations that arise from optimization passes in JIT engines continue to elude state-of-the-art testing methods. While such flaws might seem unremarkable at first glance, they are often still exploitable in practice. In this paper, we propose a novel technique for effectively uncovering this class of subtle bugs during fuzzing. The key idea is to take advantage of the tight coupling between a JavaScript engine's interpreter and its corresponding JIT compiler as a domain-specific and generic bug oracle, which in turn yields a highly sensitive fault detection mechanism. We have designed and implemented a prototype of the proposed approach in a tool called Jit-Picker. In an empirical evaluation, we show that our method enables us to detect subtle software faults that prior work missed. In total, we uncovered 32 bugs that were not publicly known and received a $10.000 bug bounty from Mozilla as a reward for our contributions to JIT engine security. CCS CONCEPTS • Security and privacy → Browser security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper33
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard 等S&P 2024 · 被引用 69 次
- Validating JIT Compilers via Compilation Space ExplorationCong Li, Yanyan Jiang, Chang Xu, Zhendong SuSOSP 2023 · 被引用 22 次
- Translation Validation for JIT Compiler in the V8 JavaScript EngineSeungwan Kwon, Jaeseong Kwon, Wooseok Kang, Juneyoung Lee 等ICSE 2024 · 被引用 19 次
- Icarus: Trustworthy Just-In-Time Compilers with Symbolic Meta-ExecutionNaomi Smith, Abhishek Sharma, John Renner, David Thien 等SOSP 2024 · 被引用 17 次
- Towards Better Semantics Exploration for Browser FuzzingChijin Zhou, Quan Zhang, Lihua Guo, Mingzhe Wang 等OOPSLA 2023 · 被引用 15 次
它引用的顶会 Paper25
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 被引用 1,026 次
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik 等NDSS 2019 · 被引用 413 次
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig 等NDSS 2019 · 被引用 291 次
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 被引用 178 次
相关 Paper
- FUZZILLI: Fuzzing for JavaScript JIT Compiler VulnerabilitiesSamuel Groß, Simon Koch, Lukas Bernhard, Thorsten Holz 等NDSS 2023
- FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT CompilerJunjie Wang, Zhiyi Zhang, Shuang Liu, Xiaoning Du 等USENIX Security 2023
- OptFuzz: Optimization Path Guided Fuzzing for JavaScript JIT CompilersJiming Wang, Yan Kang, Chenggang Wu, Yuhao Hu 等USENIX Security 2024 · 被引用 7 次
- DUMPLING: Fine-grained Differential JavaScript Engine FuzzingLiam Wachter, Julian Gremminger, Christian Wressnegger, Mathias Payer 等NDSS 2025
- BCFuzz: Bytecode-Driven Fuzzing for JavaScript EnginesJiming Wang, Chenggang Wu, Jikai Ren, Yuhao Hu 等ASE 2025 · 被引用 1 次
