Chrome VMP Protection Flow

VM-based protection around Chrome native media modules: process boundary, dispatcher, encoded state, integrity checks

Chrome VMP protection architecture Architecture diagram showing Chrome renderer, Mojo IPC, CDM utility process, VMP dispatcher, protected state, analysis boundaries and output trust boundary. Chrome Runtime Boundary Renderer / Browser side CDM Utility Process: sandboxed native module Web Page EME / media License server response EME API MediaKeys Mojo IPC challenge / frames Video decoded frame plaintext boundary Shared memory handle YUV / frame data CDM Host ABI CreateCdmInstance UpdateSession license ingest stack-only K Decrypt CENC subsamples no naked key VMP / white-box core VM Dispatcher state machine / CFF Encoded State K xor M / tables internal encodings Integrity Loop .text hash / anti-debug patch detection Bytecode compressed blob Research Observability perf / heap snapshot / trace sees dispatcher and encoded state not a stable key schedule browser / renderer security / tamper protected VM core encoded assets plaintext output boundary

Protection Target

  • • Keep keys outside stable heap observables
  • • Replace algorithm shape with VM dispatch noise
  • • Bind useful state to session and runtime context

Hardening Layer

  • • Code integrity checks detect inline patching
  • • Anti-debug logic raises analysis cost
  • • IPC and sandboxing narrow direct attack surfaces

Remaining Boundary

  • • Legitimate playback still produces plaintext frames
  • • VMP protects keys, not every downstream buffer
  • • Analysis should focus on semantic trust transitions