WebAssembly (WASM) is a high-performance compiled language for execution in web browsers that interoperates with JavaScript. In general, the wasm compiler in the browser is integrated into the javascript engine, which has proven to be an important attack surface in browsers over the past years. Protecting the security of the WASM compiler is a matter of security for the browser, and thus for the users. We have seen a remote code execution vulnerability in the wasm compiler previously (pwn2own2021), and it seems that no public research has continued to demonstrate vulnerabilities from this attack surface since then. In fact, over the past year, the number of commits of the Webassembly compiler in Webkit has surpassed that of javascript JIT and introduced some new features based on the wasm 2.0 specification such as Exceptions, Tail Call, SIMD, etc. In this case, the security of the wasm compiler should be re-emphasized......
By: Zong Cao (P1umer) , Yeqi Fu (Q1IQ) , Fangming Gu (afang5472) , Bohan Liu , Zheng Wang (xmzyshypnc)
Full Abstract and Presentation Materials:
#attacking-the-webassembly-compiler-of-webkit-30926
1 view
0
0
1 month ago 00:02:14 1
Futures of The Past - Cold Hearted Spies
1 month ago 00:00:15 1
Photographer Captures Arowana and Snake Battle on Camera
1 month ago 00:04:17 1
On Cam: Russian Jets Pound ‘West-Backed’ Rebels In Syria As Putin Comes To Rescue ‘Anti-Israel’ Ally
2 months ago 00:03:47 1
Central Israel Under Attack: Missiles Pummel Tel Aviv Suburbs; Hezbollah Bombs North | Watch
2 months ago 00:07:03 1
Combat Geometry in Pekiti Tirsia Kali | Grand Tuhon Supremo Leo T. Gaje Jr. | Filipino Martial Arts