Fuzzing for redundancy elimination vulnerabilities in just-in-time JavaScript engines

Yazhuo Jin · 2024

JIT (Just-In-Time) compilers are among the intricate components within JavaScript engines, harboring numerous potential security vulnerabilities. Fuzzing, an advanced vulnerability discovery technique, is frequently employed for detecting vulnerabilities in JavaScript engines. However, employing fuzzing to detect vulnerabilities caused by JIT compiler optimizations poses significant challenges. To facilitate the testing of JIT compiler components in JavaScript engines using fuzzing, this paper introduces a template combination strategy. This template guides the generation of test cases capable of triggering vulnerabilities in JIT compiler redundancy elimination optimizations during the fuzzing process, resulting in the implementation of the AimJITFuzz system. Specifically, by analyzing existing CVEs generated by JIT optimizations, the vulnerability mechanisms arising from JIT compiler optimizations are summarized. Subsequently, code block combination templates are designed based on these vulnerability mechanisms. These templates are utilized to guide the splitting of existing proof-of-concept (POC) codes into a code block pool and to guide the combination of code blocks to form test cases capable of triggering JIT compiler optimizations. Experimental results demonstrate that the AimJITFuzz system can generate test cases capable of triggering JIT optimization vulnerabilities based on the vulnerability mechanisms. Within one week, AimJITFuzz triggers six times more crashes caused by JIT optimizations compared to FUZZILLI. Moreover, AimJITFuzz achieves the maximum branch coverage within the same timeframe compared to other tools.

Read the paper · More papers on PaperTik