A Mere Mortal's Introduction to JIT Vulnerabilities in JavaScript Engines
JavaScript engines are crucial components within web browsers that handle the execution of JavaScript code found in web pages. For instance, when a user navigates to a website containing JavaScript code, the JavaScript engine is what brings the code to life. These engines are typically written in languages like C or C++. They suffer from being vulnerable to exploitation due to their complexity and the fact that they must run untrusted code.
JIT compilers, short for Just-In-Time compilers, are essential parts of JS engines. They are responsible for enhancing the performance of JavaScript code execution. To grasp their role, let's contrast the functioning of a JavaScript engine with and without a JIT compiler.
Without a JIT compiler, a JS engine would parse incoming JavaScript code. This code is then transformed into an abstract syntax tree, which is further converted into bytecode. This bytecode is executed by the engine's interpreter, often referred to as the baseline interpreter. In V8—the JavaScript engine used in Google Chrome—the baseline interpreter is known as Ignition.
Despite not providing optimized performance, the baseline interpreter still enables a functional execution environment for JavaScript. JIT compilers are, in essence, optional optimizers that can enhance performance. Some JS engines—those not used in browsers—might not have JIT compilers at all. However, modern browsers often offer users the option to disable JIT compilation if they so choose. Yet, browser vendors usually ensure JIT compilers are present in their products.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.