Skip to content

JIT-Spray revisited

A 2026 read of the JIT-Spray work originally published by DSecRG circa 2009-2010. Bookmark this page; the full piece lands in the next publication cycle. Filed under Heritage revisits.

The original JIT-Spray research was Alexander Sotirov’s work in 2007, refined and extended by the DSecRG team around 2009-2010. The technique uses a JIT compiler (originally Flash, later browser JavaScript engines) to spray executable shellcode through the JIT-emitted page cache, bypassing DEP without ROP. The headline paper, “JIT-Spray Attacks and Advanced Shellcode,” was presented at Hack-in-the-Box and remains the canonical reference.

In 2026 the technique is largely closed in production browsers (W^X JIT pages on V8, JIT randomization on JavaScriptCore, Edge’s Arbitrary Code Guard) but it surfaces periodically in less-hardened JITs and in WASM contexts. We will work through the 2026 mitigation landscape paper-by-paper in the full revisit.

Original research preserved at the Internet Archive. The full 2026 revisit is on the schedule.