arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.20698cs.CR

从嗡嗡声到轰鸣:通过分段定向模糊测试检测 Electron 应用程序中的消息进展漏洞

Buzz to Boom: Detecting Message Progression Vulnerabilities in Electron Applications via Segmented Directed Fuzzing

Jianjia Yu, Zhengyu Liu, Ziyang Li, Yu Sun, Yinzhi Cao

首次发表
浏览论文内容

中文总结 AI 辅助

研究针对 Electron 应用程序中消息进展漏洞的检测,提出 Proton 分段定向模糊测试框架,沿消息传递边界分解模糊测试,从各进程合成崩溃输入验证利用,经对 589 个应用评估发现 23 个零日漏洞,推动相关修复并获致谢与赏金。

中文摘要 AI 辅助

Electron 是用于使用 Web 技术构建跨平台桌面应用程序的流行框架。此类应用程序由具有不同权限级别的多个进程组成,通过消息传递进行通信。当进程间消息携带攻击者控制的输入时,可能传播到特权 API,这种消息传播行为被称为消息进展漏洞(MPV)。利用 MPV 具有挑战性,因为通常需要多个步骤。现有 Electron 安全工作仅研究不安全配置和恶意文档对象模型(DOM)内容,无法检测或利用此类需通过复杂跨进程利用触发的漏洞。我们提出了 Proton,一种用于检测 MPV 的分段定向模糊测试框架。我们的关键见解是沿消息传递边界将端到端模糊测试分解为每个进程的段,每个段的模糊测试目标要么是在当前进程中到达一个汇点,要么是将有效负载传播到下一个进程以探索另一个进程。在第二种情况下,消息为下一段的语料库播种。最后,Proton 从每个进程合成崩溃输入以验证端到端利用。我们针对 589 个真实世界的 Electron 应用程序评估了 Proton,发现了 23 个零日 MPV,其中 22 个导致操作系统命令执行,包括拥有超过 50k GitHub 星标的项目。我们负责任地披露了所有发现,目前已收到 13 份致谢、11 个修复和 11 个 CVE,包括来自 Vercel 的漏洞赏金。

英文摘要

Electron is a popular framework for building cross-platform desktop applications using web technologies. Such applications consist of multiple processes with different privilege levels that communicate via message passing. When inter-process messages carry attacker-controlled inputs, they can propagate across processes and reach privileged APIs, e.g., command execution. Such a message propagation behavior is characterized as Message Progression Vulnerabilities (MPVs). The exploitation of MPVs is challenging because it often requires multiple steps, e.g., first arbitrary code execution in one process via message passing, and then command injection in another process using another message crafted in the first process. To our knowledge, existing works on Electron security only study unsafe configurations and malicious Document Object Model (DOM) content, i.e., they cannot detect or exploit these vulnerabilities that need to be triggered by complex cross-process exploits via message passing. We present Proton, a segmented directed fuzzing framework for detecting MPVs. Our key insight is to decompose end-to-end fuzzing into per-process segments along message-passing boundaries, where the goals of fuzzing each segment are either: (i) reaching a sink in the current process or (ii) propagating the payload to the next process, to enable the exploration of another process. In the second case, the messages seed the corpus of the next segment. Finally, Proton synthesizes crash inputs from each process to validate end-to-end exploits. We evaluate Proton against 589 real-world Electron applications, resulting in 23 zero-day MPVs. Among them, 22 lead to OS command execution, including projects with over 50k GitHub stars. We responsibly disclosed all findings. To date, we have received 13 acknowledgments, 11 fixes, and 11 CVEs, including a bug bounty from Vercel.

↑