WebAssembly Under the Microscope: Study Reveals Security Issues in Popular Web Apps

The WebAssembly technology is enabling increasingly powerful web applications. However, many web apps that rely on WebAssembly contain security vulnerabilities. Researchers from paluno – The Ruhr Institute for Software Technology have investigated the potential risks for users and developed an analysis tool to improve the security of WebAssembly-powered applications.

Alongside HTML, CSS, and JavaScript, WebAssembly has now established itself as the "fourth language" of the web and is supported by all major browsers. The technology allows developers to write programs in languages such as C, C++, Go, or Rust, which can then be compiled into WebAssembly and executed in the browser with near-native performance. This advantage has led to widespread adoption among major web applications, including twitch.tv, Google Earth, Adobe Photoshop, and Zoom.

Blind Trust in WebAssembly Components

However, the technology also presents security risks, as revealed by a joint study conducted by paluno – The Ruhr Institute for Software Technology and TU Braunschweig. The researchers analyzed nearly 38,000 domains and found that over 77% of these domains load data into their WebAssembly modules without adequately verifying the sources.

According to the researchers, this practice poses a significant security risk. If a WebAssembly module contains memory corruption bugs, attackers could exploit these vulnerabilities to inject malicious code into users' browsers remotely.

To mitigate this risk, the researchers developed Wemby, an advanced analysis tool for identifying memory corruption errors in WebAssembly components. Compared to existing approaches, Wemby analyzes significantly more code in a fraction of the time.

Vulnerability in Zoom Discovered

Using Wemby, the researchers discovered a vulnerability in Zoom, which could have been exploited via manipulated video data. The affected providers were informed to take appropriate security measures.

In June 2025, the researchers will present their findings at the renowned Software Engineering Conference ISSTA in Trondheim (Norway)

 

Publication

Draissi, Oussama;Cloosters, Tobias; Klein, David; Rodler, Michael; Musch, Marius; Johns, Martin; Davi, Lucas:Wemby's Web: Hunting for Memory Corruption in WebAssembly. In:Proc. of the 34th International Symposium on Software Testing and Analysis (ISSTA). 34. Auflage. ACM, Trondheim, Norway 2025.

Contact

Name Contact

System Security (SYSSEC)

Oussama Draissi
+49 201 18-37019

Press and Public Relations

Birgit Kremer
+49 201 18-34655