English

The WASM Cloak: Evaluating Browser Fingerprinting Defenses Under WebAssembly based Obfuscation

Cryptography and Security 2025-09-01 v1 Emerging Technologies Programming Languages

Abstract

Browser fingerprinting defenses have historically focused on detecting JavaScript(JS)-based tracking techniques. However, the widespread adoption of WebAssembly (WASM) introduces a potential blind spot, as adversaries can convert JS to WASM's low-level binary format to obfuscate malicious logic. This paper presents the first systematic evaluation of how such WASM-based obfuscation impacts the robustness of modern fingerprinting defenses. We develop an automated pipeline that translates real-world JS fingerprinting scripts into functional WASM-obfuscated variants and test them against two classes of defenses: state-of-the-art detectors in research literature and commercial, in-browser tools. Our findings reveal a notable divergence: detectors proposed in the research literature that rely on feature-based analysis of source code show moderate vulnerability, stemming from outdated datasets or a lack of WASM compatibility. In contrast, defenses such as browser extensions and native browser features remained completely effective, as their API-level interception is agnostic to the script's underlying implementation. These results highlight a gap between academic and practical defense strategies and offer insights into strengthening detection approaches against WASM-based obfuscation, while also revealing opportunities for more evasive techniques in future attacks.

Keywords

Cite

@article{arxiv.2508.21219,
  title  = {The WASM Cloak: Evaluating Browser Fingerprinting Defenses Under WebAssembly based Obfuscation},
  author = {A H M Nazmus Sakib and Mahsin Bin Akram and Joseph Spracklen and Sahan Kalutarage and Raveen Wijewickrama and Igor Bilogrevic and Murtuza Jadliwala},
  journal= {arXiv preprint arXiv:2508.21219},
  year   = {2025}
}
R2 v1 2026-07-01T05:11:15.241Z