Loading…
Monday August 10, 2026 2:20pm - 2:40pm EDT
Han Zheng, EPFL; Flavio Toffalini, Ruhr-Universität Bochum; Qiang Liu and Mathias Payer, EPFL


Complex software systems, like web browsers, integrate multiple tightly-coupled components. While code reviews and fuzzing enhance code quality, eliminating all bugs remains infeasible due to large-scale projects, unpredictable cross-context interactions, and complex cross-domain dependencies. This dire situation calls for an approach that scales to this unprecedented complexity.

Inspired by informal variant analysis developed by the hacker community, we create GRAPE, a structured approach that supports analysts in writing rules to detect bugs. By focusing on code patterns, GRAPE scales effectively to large-scale code projects. Moreover, our novel variant bug model enables analysis of cross-context interactions and exploitability verification using existing bug reports, eliminating the need for cross-domain dependencies. GRAPE represents the first systematic approach to variant analysis, introducing principles for variant pattern development.

We implement a prototype of GRAPE, which scans the entire Chromium code base in only 12 minutes. GRAPE discovered 24 new bugs, with four assigned CVEs and 17, 500 USD in rewards from Chrome’s Vulnerability Rewards Program. These discoveries impact modern web browser and security-critical complex software like OpenSSL. Beyond browsers, GRAPE uncovered three logic bugs in VSCode and Azure Data Studio, one of which received a CVE from Microsoft.


https://www.usenix.org/conference/woot26/presentation/zheng
Monday August 10, 2026 2:20pm - 2:40pm EDT
Harborside Ballroom B

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link