🤖 AI Summary
This study addresses the lack of systematic understanding regarding the characteristics, root causes, and exploitation chains of JavaScript engine vulnerabilities. To this end, it presents the first comprehensive empirical investigation across four mainstream JS engines, including V8. By constructing a dataset of 241 vulnerabilities, the authors establish a taxonomy classifying both symptoms and root causes, and extract complete exploitation chains spanning from logical errors to memory violations. The findings reveal the underlying mechanisms through which logical flaws cascade into memory safety violations and identify the critical prerequisites for successful exploitation. Ultimately, this work provides actionable defensive insights for developers and security researchers, effectively bridging a significant gap in the systematic study of JavaScript engine security.
📝 Abstract
JavaScript engines are pivotal to modern web browsers, enabling the execution of dynamic and interactive web applications. However, their complexity and widespread adoption make them prime targets for attackers exploiting vulnerabilities. While existing research has focused on detecting vulnerabilities of JavaScript engines, a significant gap remains in systematically understanding the characteristics of these vulnerabilities, including their symptoms, root causes, and exploitability. This paper bridges this gap by presenting the first comprehensive empirical study on vulnerabilities in JavaScript engines, investigating their characteristics and potential exploitation strategies.
We construct a dataset comprising 241 vulnerabilities across four mainstream JavaScript engines from 2017 to 2024. Through in-depth analysis, we first develop taxonomies for symptoms and root causes. Building on this understanding, we investigate the exploitability of these vulnerabilities, identifying key prerequisites and extracting vulnerability trigger chains that demonstrate how logical errors propagate into memory safety violations. Additionally, we analyze the mitigation strategies to counter these exploits. Finally, we summarize key implications for various stakeholders, including developers and researchers, offering actionable insights to improve the security and resilience of JavaScript engines.