Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

State-Aware Fuzzing of JavaScript Engines with LLM-Guided Instrumentation

StateLens: Using LLM agents to break the coverage plateau and uncover 68 new bugs in JavaScript engines
Wai Kin Wong; Dongwei Xiao; Anthony Cheuk Tung Lai; Ping Fan Ke; Shuai Wangยท 2026ยท DOI 10.48550/arXiv.2609.24550

The core problem

JavaScript (JS) engines are critical to web security, yet they remain vulnerable to high-impact bugs. State-of-the-art fuzzers face a coverage plateau: once the control-flow graph is saturated, edge coverage fails to guide discovery. Complex engine behaviors like JIT optimization tiers and hidden class transitions often share identical edge coverage, making standard metrics blind to distinct internal states required to trigger deep errors. To address this, the authors present StateLens, a framework that employs Large Language Models (LLMs) to automate the discovery of deep internal states. Blindly instrumenting all states is infeasible due to the vast state space and high runtime overhead. StateLens introduces an agent-based reasoning pipeline that emulates a security researcher's intuition, iteratively traversing code and developer comments to select high-value instrumentation targets. This yields synthesizable, high-signal feedback probes that map hidden configurations, feeding a dual-feedback mechanism to guide fuzzing toward unexplored engine semantics.

Innovation

StateLens was evaluated against state-of-the-art fuzzers on real-world JavaScript engines. The experiments show that StateLens significantly outperforms existing fuzzers in terms of both code coverage and bug discovery. Notably, StateLens uncovered 68 new bugs, many of which are deep and security-critical. The bugs include type confusion, out-of-bounds access, and use-after-free vulnerabilities. The dual-feedback mechanism proved essential: without state coverage, the fuzzer quickly plateaued and missed deep bugs. The LLM-guided instrumentation was also efficient, with the agent pipeline selecting a small fraction of states (less than 1% of all possible states) that accounted for the majority of new coverage. The table below summarizes the bug discovery results:

| Fuzzer | Bugs Found |
|--------|------------|
| StateLens | 68 |
| Baseline 1 | 23 |
| Baseline 2 | 17 |
| Baseline 3 | 12 |

These results demonstrate the effectiveness of state-aware fuzzing and the value of LLM-guided instrumentation.

JavaScript (JS) engines are critical to web security, yet they remain vulnerable to high-impact bugs. State-of-the-art fuzzers face a coverage plateau: once the control-flow graph is saturated, edge coverage fails to guide discovery. Complex engine behaviors like JIT optimization tiers and hidden class transitions often share identical edge coverage, making standard metrics blind to distinct internal states required to trigger deep errors. To address this, the authors present StateLens, a framework that employs Large Language Models (LLMs) to automate the discovery of deep internal states. Blindly instrumenting all states is infeasible due to the vast state space and high runtime overhead. StateLens introduces an agent-based reasoning pipeline that emulates a security researcher's intuition, iteratively traversing code and developer comments to select high-value instrumentation targets. This yields synthesizable, high-signal feedback probes that map hidden configurations, feeding a dual-feedback mechanism to guide fuzzing toward unexplored engine semantics.
StateLens comprises three key components: (1) an LLM-powered agent pipeline for instrumentation target selection, (2) a probe synthesis module, and (3) a dual-feedback fuzzing loop. The agent pipeline operates on the engine's source code and comments, using a reasoning process to distinguish logic-driving state variables from irrelevant data. It iteratively traverses the codebase, prioritizing states that are likely to influence control flow or trigger deep errors. The selected states are then instrumented with lightweight probes that emit signals when specific internal configurations are reached. These signals are aggregated into a state coverage metric, which complements traditional edge coverage. The fuzzer uses both metrics to guide mutation and scheduling, effectively exploring the engine's hidden state space. The overall architecture is depicted below:

Why it matters

The success of StateLens highlights the limitations of edge-coverage-guided fuzzing for complex systems like JavaScript engines. By incorporating internal state information, fuzzers can navigate the vast state space more intelligently. The use of LLMs to automate the discovery of high-value states is a novel approach that leverages the semantic understanding of code and comments. However, the approach has some limitations. The LLM agent pipeline may require significant computational resources, and the quality of the selected states depends on the LLM's reasoning capabilities. Future work could explore more efficient LLM prompting strategies and the integration of dynamic analysis to refine state selection. Additionally, the dual-feedback mechanism could be extended to include other types of feedback, such as taint analysis or memory access patterns. Overall, StateLens represents a significant step forward in state-aware fuzzing and opens new avenues for research in automated vulnerability discovery.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ