In brief

  • Fuzzing advances move beyond passive discovery by instrumenting the engine for fine-grained differential state extraction and combining dynamic symbolic execution with interaction synthesis.
  • Hardware and firmware attack surfaces expand as researchers successfully inject faults into Hall-effect keyboards and systematically uncover undocumented, privileged interfaces in IoT devices.

DUMPLING: Fine-grained Differential JavaScript Engine Fuzzing

  • A new differential fuzzer that compares interpreted and optimized JIT compiled execution by instrumenting the JavaScript engine itself, allowing introspection in the middle of JIT compiled functions.
  • Previous differential fuzzing techniques relied on inserting JS functions to read states, which hindered JIT optimization and struggled to discover subtle bugs where miscalculations happen before memory corruption.
  • DUMPLING found eight new bugs in the V8 engine, demonstrating the effectiveness of high-frequency fine-grained execution state extraction.

Wachter, L. et al. “DUMPLING: Fine-grained Differential JavaScript Engine Fuzzing.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/dumpling-fine-grained-differential-javascript-engine-fuzzing/

DOM-XSS Detection via Webpage Interaction Fuzzing and URL Component Synthesis

  • Prior automated detection for DOM-XSS missed vulnerabilities requiring user interaction to execute event handlers and lacked discovery of code paths unlocked by specific URL components like GET parameters.
  • SWIPE combines user interaction fuzzing with dynamic symbolic execution to synthesize URL parameters and fragments, actively exploring previously unreached event-driven code paths.
  • Running SWIPE on 44,480 URLs found 15% more vulnerabilities than prior tools and 20 new vulnerabilities unlocked directly by the synthesized URL parameters and fragments.

Sabino, N. et al. “DOM-XSS Detection via Webpage Interaction Fuzzing and URL Component Synthesis.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/dom-xss-detection-via-webpage-interaction-fuzzing-and-url-component-synthesis/

EAGLEYE: Exposing Hidden Web Interfaces in IoT Devices via Routing Analysis

  • Hidden web interfaces in IoT firmware introduce severe risks but evade traditional bug detection because they lack obvious static patterns or fuzzing feedback.
  • EAGLEYE analyzes public interface requests to extract routing tokens (e.g., action names) and uses LLMs to deduce the pattern, building a high-quality dictionary for directed black-box fuzzing.
  • The tool discovered 79 hidden interfaces across 13 commercial IoT devices—yielding 29 unknown vulnerabilities like command injection and backdoors.

Liu, H. et al. “EAGLEYE: Exposing Hidden Web Interfaces in IoT Devices via Routing Analysis.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/eagleye-exposing-hidden-web-interfaces-in-iot-devices-via-routing-analysis/

DualStrike: Accurate, Real-time Eavesdropping and Injection of Keystrokes on Commodity Keyboards

  • DualStrike demonstrates the first non-invasive remote attack capable of both keystroke eavesdropping and per-key injection targeting commodity Hall-effect keyboards.
  • The attack leverages a custom electromagnet design for high-frequency magnetic spoofing and a magnetometer-based listening mechanism to compromise the magnetic continuous-motion sensors without hardware modifications.
  • The attack achieves over 98.9% injection accuracy across six models and can maintain 98.5% accuracy even with a 4 cm displacement offset.

Chen, X. et al. “DualStrike: Accurate, Real-time Eavesdropping and Injection of Keystrokes on Commodity Keyboards.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/dualstrike-accurate-real-time-eavesdropping-and-injection-of-keystrokes-on-commodity-keyboards/