Reviving JIT Vulnerabilities: Unleashing the Power of Maglev Compiler Bugs on Chrome Browser

No ratings

Presented at BlackHat Europe 2023 by

The JIT compiler is a complex and critical component for browsers. It plays a significant role in improving their performance. It compiles and optimizes JavaScript code into assembly code based on feedback and speculation, speeding up the execution. However, certain handling cases and security checks may be sacrificed for the sake of performance, resulting in the potentially exploitable flawed assembly code. Turbofan JIT Compiler has attracted extensive vulnerability research attention in recent years, exposing numerous remote code execution vulnerabilities. The significant threat also garnered Google's attention. The number of vulnerabilities has gradually decreased with the unrelenting effort of the V8 security team. In February 2022, the V8 team began the development work on the Maglev compiler. This is a new mid-tier JIT Compiler that has demonstrated substantial performance enhancements during testing. Will the new compiler introduce new security issues? Is there any experience from previous security research that can be applied to Maglev research?In this presentation, we will investigate the design principles of Maglev. Then we will share our experience in conducting vulnerability research and exploitation of the Maglev JIT Compiler based on our understanding of Turbofan. Firstly, we will compare and analyze the design principles of Maglev and Turbofan, thereby identifying the potential attack surface of Maglev. Next, we will demonstrate how to borrow security research experience from Turbofan to Maglev. We have improved the vulnerability exploration methods from three perspectives: Crash-based Fuzzing, Correctness-oriented fuzzing, and CodeQL in order to efficiently find vulnerabilities. Through this methodology, we found numerous bugs in Maglev, ultimately identifying and reporting 7 high-risk vulnerabilities. We will summarize and present the intriguing attack surface encountered during our research. Finally, we will demonstrate the exploitation of one of these vulnerabilities, achieving render RCE.We hope to enhance the security of Maglev by sharing our methods for bug hunting in this field. Additionally, we also hope to provide experience for vulnerability research in other similar modules.