logoalt Hacker News

The Mysterious Realm of JavaScriptCore (2021)

34 pointsby programlast Thursday at 8:33 AM6 commentsview on HN

Comments

epolanskilast Thursday at 1:10 PM

I've often thought about the possibility of implementing a language that can compile directly to optimized byte code (either for V8 or JSC), in order to get "hot code" that does not need runtime optimization, has anybody explored this idea?

show 2 replies
N_Lenstoday at 12:25 AM

Author used CodeQL to rediscover a CVE in JSC that was exploited by Pwn2Own in 2018. Very interesting. I guess now with increasing automation we'll see more CVE discovery through such tools.

gsf_emergency_6today at 12:13 AM

Author's talk from around that time (Apr 2021)

https://youtu.be/7qyKZOjhg94

[Finding] JS bugs in JSC with CodeQL