Collected research
Finding and Preventing Bugs in JavaScript Bindings
JavaScript runtimes reach native code through C++ binding layers that must translate types, state and failure between the two languages. Static checkers for crash-, type- and memory-safety violations in Node.js, Blink, the Chrome extension system and PDFium produced 81 working exploits, including out-of-bounds access and use-after-free, plus a safe wrapper API for V8.
Record
- Researcher
- Fraser Brown, Shravan Narayan, Riad S. Wahby, Dawson Engler, Ranjit Jhala and Deian Stefan
- Published by
- mlfbrown.com
- Format
- Whitepaper
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Fraser Brown, Shravan Narayan, Riad S. Wahby, Dawson Engler, Ranjit Jhala and Deian Stefan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .