Alongside HTML, CSS, and JavaScript, WebAssembly has now established itself as the "fourth language" of the web and is supported by all major browsers. The technology allows developers to write programs in languages such as C, C++, Go, or Rust, which can then be compiled into WebAssembly and executed in the browser with near-native performance. This advantage has led to widespread adoption among major web applications, including twitch.tv, Google Earth, Adobe Photoshop, and Zoom.
Blind Trust in WebAssembly Components
However, the technology also presents security risks, as revealed by a joint study conducted by paluno – The Ruhr Institute for Software Technology and TU Braunschweig. The researchers analyzed nearly 38,000 domains and found that over 77% of these domains load data into their WebAssembly modules without adequately verifying the sources.
According to the researchers, this practice poses a significant security risk. If a WebAssembly module contains memory corruption bugs, attackers could exploit these vulnerabilities to inject malicious code into users' browsers remotely.
To mitigate this risk, the researchers developed Wemby, an advanced analysis tool for identifying memory corruption errors in WebAssembly components. Compared to existing approaches, Wemby analyzes significantly more code in a fraction of the time.
Vulnerability in Zoom Discovered
Using Wemby, the researchers discovered a vulnerability in Zoom, which could have been exploited via manipulated video data. The affected providers were informed to take appropriate security measures.
In June 2025, the researchers will present their findings at the renowned Software Engineering Conference ISSTA in Trondheim (Norway).
Publication
Draissi, Oussama;Cloosters, Tobias; Klein, David; Rodler, Michael; Musch, Marius; Johns, Martin; Davi, Lucas:Wemby's Web: Hunting for Memory Corruption in WebAssembly. In:Proc. of the 34th International Symposium on Software Testing and Analysis (ISSTA). 34. Auflage. ACM, Trondheim, Norway 2025.