ICSE 2026
Sun 12 - Sat 18 April 2026 Rio de Janeiro, Brazil
Fri 17 Apr 2026 11:45 - 12:00 at Oceania II - Testing and Analysis 16 Chair(s): Andreas Zeller

JavaScript engines are a fundamental part of modern browsers, and many efforts have been invested in testing them to enhance their security. However, the incorporation of WebAssembly into JavaScript engines introduces new attack surfaces that have not received sufficient attention. Existing fuzzers for JavaScript engines primarily focus on JavaScript, neglecting WebAssembly code and its interactions with JavaScript. We introduce Mad-Eye, the first fuzzer that can test the JavaScript-WebAssembly interaction using a novel cross-language code fusion technique. Evaluations of Mad-Eye on V8, SpiderMonkey, and JavaScriptCore detected 21 previously unknown vulnerabilities, with 18 confirmed and 13 fixed and merged into mainstream browsers, who acknowledged our reports with vulnerability bounties.

Fri 17 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

11:00 - 12:30
Testing and Analysis 16Research Track / SE In Practice (SEIP) at Oceania II
Chair(s): Andreas Zeller CISPA Helmholtz Center for Information Security
11:00
15m
Talk
Parse this! Summoning Context-Sensitive Inputs with Goblin
Research Track
Robert Lorch The University of Iowa, Muhammad Daniyal Pirwani Dar Stony Brook University, Cesare Tinelli University of Iowa, Omar Chowdhury Stony Brook University
11:15
15m
Talk
Context-Free Property Oriented Fuzzing
Research Track
Jiaqiang Yao College of Computer, National University of Defense Technology, Meixi Liu National University of Defense Technology, Changsha, China, Zhenbang Chen College of Computer, National University of Defense Technology, Yongchao Xing College of Computer, National University of Defense Technology, Jinjian Luo College of Computer, National University of Defense Technology, Yunlai Luo National University of Defense Technology, Guofeng Zhang College of Computer, National University of Defense Technology, Yufeng Zhang Hunan University, Ji Wang National University of Defense Technology
11:30
15m
Talk
Metamorphic Fuzzing for Multi-Agent Path Finding Algorithms
Research Track
Luxia Lin Institute of Software, Chinese Academy of Sciences, China, xudong zhang , Shihao Zhu State Key Laboratory of Computer Science,Institute of Software,Chinese Academy of Sciences,China, Yan Cai Institute of Software at Chinese Academy of Sciences
11:45
15m
Talk
Fuzzing JavaScript Engines by Fusing JavaScript and WebAssembly
Research Track
Jiayi Lin The University of Hong Kong, Changhua Luo The University of Hong Kong; Wuhan University, Mingxue Zhang Zhejiang University, Lanteng Lin The University of Hong Kong, Penghui Li Columbia University, Chenxiong Qian University of Hong Kong
12:00
15m
Talk
TypeJinja: Static Type Checking of Jinja Templates at dbt LabsVirtual Attendance
SE In Practice (SEIP)
Cheng Ding The University of Texas at Austin, Zhong Xu dbt Labs, Michael Levin dbt Labs, Wolfram Schulte dbt Labs, Milos Gligoric The University of Texas at Austin
Media Attached
12:15
15m
Talk
Principles and Practices of Large-Scale Code Analysis at Ant Group: A Data- and Logic-Oriented Approach
SE In Practice (SEIP)
Xiaoheng Xie Ant Group, Gang Fan Huawei Hong Kong Research Centre, Xiaojun Lin Ant Group, Ang Zhou Ant Group, Shijie Li Ant Group, Xunjin Zheng Ant Group, Yinan Liang Ant Group, Yu Zhang Ant Group, Na Yu Ant Group, Haokun Li Ant Group, Xinyu Chen Ant Group, Yingzhuang Chen Ant Group, Yi Zhen Ant Group, Dejun Dong Ant Group, Xianjin Fu Ant Group, Jinzhou Su Ant Group, Fuxiong Pan Ant Group, Pengshuai Luo Ant Group, Youzheng Feng Ant Group, Ruoxiang Hu Ant Group, Hanyang Guo School of Software Engineering, Sun Yat-sen University, Jing Fan Ant Group, Xiao Xiao Sourcebrella Inc., Peng Di Ant Group & UNSW Sydney