Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis

Yuxi Ling

34th USENIX Security Symposium (USENIX Security '25) · Day 1 · Software Security 1

Overview

This technical article delves into the research presented in "Narrowbeer: A Practical Replay Attack Against the Widevine DRM," a paper by Florian Roudot and Mohamed Sabt from IRISA, Univ Rennes, and CNRS, presented at USENIX Security. The work investigates the security of Google's Widevine Digital Rights Management (DRM) system, a widely deployed software-based solution used by major streaming services like Netflix, Prime Video, and HBO Max to protect premium content from piracy. Unlike previous research that primarily focused on breaking Widevine's internal software protections or cryptographic mechanisms, this paper shifts its attention to how Widevine interacts with its host environment, specifically the operating system and web browser, concerning fundamental security properties like randomness and time.

Read the paper · Download the PDF (PDF) · Slides

Paper abstract

Streaming services like Netflix, Prime Video, and HBO Max rely on DRM solutions to ward off piracy. By enabling the distribution of encrypted content, DRM systems prevent subscribed users from downloading the streamed content, as well as unauthorized users from having access to it. Google Widevine, one of the most deployed DRMs, provides a fully software-based solution on desktop platforms to ensure portability. In this paper, we empirically investigate the security protections implemented by Widevine to counter an attacker tampering with its interactions within its environment, namely with the operating system and the hosting browser. Focusing on randomness and time, we uncover new flaws in the Widevine license acquisition process, particularly targeting the freshness and expiration of the licenses. To demonstrate the effectiveness of our findings, we develop Narrowbeer, a practical replay attack allowing legitimate users to generate never-expiring licenses, and enabling unauthorized users to reuse these licenses to access premium content without subscription. Finally, we validate our attack against real-world streaming services by succeeding in repeatedly playing the same license on different desktop devices.

Visual summary for Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis by Yuxi Ling
Visual summary for Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis by Yuxi Ling

Narrowbeer: A Practical Replay Attack Against the Widevine DRM

Speakers: Florian Roudot (IRISA), Mohamed Sabt (IRISA), Univ Rennes (IRISA), CNRS (IRISA)

Conference: USENIX Security

YouTube: N/A (Paper-only presentation)

Overview

This technical article delves into the research presented in "Narrowbeer: A Practical Replay Attack Against the Widevine DRM," a paper by Florian Roudot and Mohamed Sabt from IRISA, Univ Rennes, and CNRS, presented at USENIX Security. The work investigates the security of Google's Widevine Digital Rights Management (DRM) system, a widely deployed software-based solution used by major streaming services like Netflix, Prime Video, and HBO Max to protect premium content from piracy. Unlike previous research that primarily focused on breaking Widevine's internal software protections or cryptographic mechanisms, this paper shifts its attention to how Widevine interacts with its host environment, specifically the operating system and web browser, concerning fundamental security properties like randomness and time.

The core contribution of this research is the discovery of new flaws in Widevine's license acquisition process, particularly regarding the freshness and expiration of content licenses. The authors developed a practical replay attack, dubbed Narrowbeer, which allows legitimate subscribers to generate licenses that effectively "never expire" and, crucially, enables unauthorized users to reuse these licenses to access premium content without a subscription. This attack bypasses the fundamental DRM security model, allowing content to be played repeatedly and shared across different desktop devices, effectively transforming content providers' streaming infrastructure into a pirate distribution network.

The significance of Narrowbeer lies in its demonstration that even robust cryptographic mechanisms and anti-debugging techniques within a software-only DRM can be undermined by manipulating external dependencies like system-level time and randomness. This highlights a critical vulnerability in the design philosophy of software-based DRMs, which often prioritize portability over the robust security offered by hardware-backed solutions. The findings call for a more holistic approach to DRM security, emphasizing the need for hardware-assisted protections in environments where attackers can control system resources, and challenging the long-held assumption that Widevine's weakest link lies in its white-box cryptography or obfuscation.

Background

Digital Rights Management (DRM) systems are foundational to the business models of modern streaming services, designed to prevent unauthorized access and distribution of copyrighted digital content. Historically, DRMs were integrated into proprietary media plugins like Adobe Flash or Microsoft Silverlight. However, with the advent of HTML5's <video> tag and the W3C Encrypted Media Extensions (EME) standard [22], DRM systems became standardized interfaces between web pages and client-side Content Decryption Modules (CDMs). This standardization led to the widespread adoption of a few dominant DRM solutions, including Google Widevine, Microsoft PlayReady, and Apple FairPlay.

Widevine stands out due to its exceptional cross-platform and cross-browser compatibility, supporting Windows, Android, Linux, macOS, and all major browsers. This portability, however, comes with a significant security trade-off: on desktop platforms, Widevine deploys a software-only CDM module running as a user-land process. Such software-based CDMs are inherently less secure than their hardware-backed counterparts (e.g., Intel SGX or ARM TrustZone) because they operate in an environment where a sufficiently powerful attacker can have full control over the underlying system. To compensate, Widevine integrates numerous proprietary software security mechanisms, including code obfuscation and anti-debugging techniques, to deter tampering.

The typical DRM workflow involves three main components:

  1. Content Delivery Network (CDN): Encrypts and distributes the media content.
  2. License Server: Issues decryption keys and usage rights (a license) to legitimate users upon request.
  3. Content Decryption Module (CDM): Resides on the user's device, receives the license, decrypts the content, and enforces usage rights (e.g., expiration time).

When a user selects content, the CDM generates a license request, which is sent to the license server. If approved, the server returns a license response containing the necessary keys and policies. The CDM then loads these keys, enabling the playback of encrypted content. The EME protocol standardizes this interaction.

Prior research on Widevine [9, 10, 15, 20, 24] has largely focused on extracting unencrypted media by directly attacking the CDM's software protections, leading to an ongoing "patch-and-hack" cycle. This approach implicitly assumes that Widevine's security relies solely on the unbroken nature of its software defenses. The authors of Narrowbeer, however, challenge this assumption. They argue that despite Widevine's widespread deployment, little attention has been paid to other attack vectors and attacker models. Instead of targeting the confidentiality of license keys or breaking software protections, this paper investigates the enforcement of expiration times and the prevention of license replay against an attacker who can maliciously intercept and manipulate calls to operating system resources. This shift in focus aims to uncover design flaws that are less about specific software vulnerabilities and more about the fundamental assumptions of a software-only DRM operating in a potentially compromised environment.

Key Findings

The research presents three main contributions, each building upon the other to reveal fundamental weaknesses in Widevine's desktop implementation:

  1. Detailed Analysis of Widevine's EME Integration and System Interactions: The authors thoroughly dissected how Widevine integrates into EME-supporting desktop browsers, highlighting its critical interactions with the browser (as the EME user-agent) and the underlying operating system. They identified that Widevine relies on the OS for two crucial security resources: time and randomness. This analysis provided a foundation for understanding which interactions could be tampered with to assess Widevine's security, specifically noting that the browser facilitates time acquisition for Widevine, while Widevine directly requests random bytes from the OS.
  2. Identification of a Design Flaw in License Expiration Enforcement: Through empirical investigation, the researchers uncovered a significant design flaw in how Widevine enforces license expiration. They found that an attacker with control over system time can effectively use a license beyond its specified expiration period. This vulnerability stems from the Widevine CDM's failure to enforce a logical constraint: that the license load timestamp (T2) must always be greater than or equal to the license request timestamp (T1). By manipulating these timestamps, an attacker can create licenses with virtually indefinite lifetimes.
  3. Development of Narrowbeer: A Practical Replay Attack: Building on the previous findings, the paper introduces Narrowbeer, a novel replay attack that allows an attacker to reuse a previously acquired valid license response indefinitely. This attack enables anyone, including users without subscriptions, to access premium content on any desktop device. By controlling system time and randomness, Narrowbeer ensures that the derivation buffer (used to generate cryptographic keys for a session) remains constant across different sessions. This consistency tricks the Widevine CDM into accepting previously harvested license responses, effectively bypassing the license server and traditional subscription models. The attack demonstrates that Widevine's "weakest link" is not its sophisticated white-box cryptography or obfuscation but rather its reliance on external, manipulable sources for randomness and time.

These findings collectively highlight the inherent limitations of relying solely on software-based protections for DRM systems, especially when the attacker has control over system-level resources. The research underscores the need for a more comprehensive security approach that may incorporate hardware-based protection mechanisms to secure critical operations like timekeeping and random number generation.

Technical Deep Dive

The Narrowbeer attack exploits fundamental design choices in Widevine's desktop implementation, particularly its reliance on the operating system for critical security primitives like time and randomness. The authors conducted a meticulous empirical investigation into Widevine's interactions and vulnerabilities.

Widevine EME Integration: Browser and System Views

The paper first details Widevine's integration into the Encrypted Media Extensions (EME) ecosystem on desktop browsers (Chrome, Firefox, Edge).

  • Browser View (Native Calls): The browser, acting as the EME user-agent, dynamically loads the Widevine CDM. Key interactions include:
  • Initialization: The browser calls VerifyCdmHost (part of Verified Media Path, VMP) to check binary integrity, then InitializeCdmModule and CreateCdmInstance.
  • License Generation: The browser initiates CreateSessionAndGenerateRequest with content-specific data. Widevine generates a license request containing a 16-byte session ID, a 16-byte request ID, content key IDs, a request time, and two 4-byte nonces. It also includes a client ID (encrypted in Privacy Mode using AES-CBC with a random privacy key and IV, then RSA-OAEP encrypted with the license server's certificate). The CDM signs this request and returns it to the browser for forwarding to the license server.
  • License Load: The license server processes the request and returns a license response containing encrypted content keys and usage rights (including Time-to-Live, TTL). The browser passes this to the CDM via UpdateSession. The CDM derives Asset Key, MAC Server Key, and MAC Client Key from a derivation buffer (which includes the request ID, first nonce, and request timestamp) and verifies integrity. The expiration time is computed, and content keys are loaded.
  • License Use and Renewal: The browser requests decryption (DecryptAndDecodeFrame/Sample). Licenses can be renewed before expiration, involving a new renewal request with the initial request ID, request time, and a counter.
  • System View (OS Resources): Widevine's portability means it relies on the OS for time and randomness.
  • Time: Widevine does not directly make gettimeofday (Linux) or GetSystemTimeAsFileTime/timeGetTime (Windows) calls. Instead, it relies on the browser to fetch the current wall time via a callback mechanism (GetCurrentWallTime). The browser also sets timers, and Widevine responds to TimerExpired calls to maintain an internal clock and track license validity.
  • Randomness: During request generation and content decryption, Widevine directly issues getrandom (Linux) or SystemFunction036/RtlGenRandom (Windows) system calls to obtain random bytes for session IDs, request IDs, nonces, RSA-PSS signature salts, and Privacy Mode keys/IVs.

Problem Statement and Threat Model

The authors define a distinct threat model: an unprivileged user with control over their own device, capable of installing binaries and running scripts. This excludes attacks that break Widevine's internal software protections (obfuscation, anti-debugging), focusing instead on vulnerabilities related to the inherent design of DRMs and their reliance on external system resources. The paper focuses on two security goals from Delaune et al. [6]:

  1. Freshness of licenses: A valid license should be loaded at most once.
  2. Enforcing expiration time: A license cannot be used beyond its specified expiration.

The attacker's goal is to violate these properties, enabling repeated playback and device-independent reuse of licenses.

Empirical Investigation: Tampering with Time and Randomness

The core of the technical deep dive involves the empirical investigation (RQ1, RQ2, RQ3).

  • RQ1: Tampering with System Communication and APIs:
  • Methodology: A custom C++ wrapper library was built to intercept all native calls between Firefox and Widevine CDM (version 4.10.2710.0). ptrace on Linux and MinHook on Windows were used to intercept system calls. The browser's GMP sandbox was disabled to allow hooking.
  • Results: On Linux, direct API calls to Widevine via the wrapper were successful. On Windows, VerifyCdmHost detected the non-browser caller, leading to a PLATFORM_TAMPERED VMP status, which could result in content degradation or refusal of license. Crucially, Widevine did not implement protections against hooking system calls; modifying arguments or return values did not crash the CDM, and VMP did not detect tracing. This confirmed that Widevine's critical dependencies (time, randomness) could be manipulated.
  • RQ2: Impact of Fixed Random Numbers:
  • Methodology: All getrandom (Linux) and RtlGenRandom (Windows) system calls used by Widevine were intercepted, and their output buffers were filled with fixed values. The impact on license requests and derivation buffers was analyzed.
  • Results: The researchers successfully mapped and fixed various random fields in the license request: 16-byte session ID, 16-byte request ID, 4-byte nonces, and 82-byte RSA-PSS signature salt. In Privacy Mode, the 16-byte AES privacy key and 16-byte IV were also fixed. However, the RSA-OAEP seed used to encrypt the privacy key could not be fixed via system calls, as Widevine's statically linked BoringSSL library could use Intel RDRAND instructions, bypassing OS calls.
  • Derivation Buffer Analysis: Experiments revealed that, without Privacy Mode, the request ID and the first nonce, along with the request timestamp, are part of the derivation buffer. With Privacy Mode, the encrypted client ID (including privacy key, IV, and the unfixable RSA-OAEP seed) is also part of this critical buffer. This unfixable seed posed a challenge for a universal replay attack.
  • RQ3: Altering Effective License Expiration Time:
  • Methodology: To hook time system calls (which are often optimized via vDSO on Linux), vDSO was disabled by modifying the process stack. gettimeofday (Linux) and GetSystemTimeAsFileTime/timeGetTime (Windows) were hooked to control the returned time.
  • Results: The authors defined key time values: T1 (request generation), T2 (license load), TTL (license server defined lifetime), and T3 (expiration time, T1 + TTL). They also introduced eTTL (effective TTL, T3 - T2).
  • Modifying T1 (request time) had no impact on the license server's response; it always issued a license based on the provided T1.
  • Crucially, the Widevine CDM does not enforce T2 ≥ T1. This is the core vulnerability.
  • Attack Method 1: Increasing Lifetime by Modifying T2: By setting T2 (load time) to a value earlier than T1 (request time), the effective TTL can be dramatically extended. For example, if T1 is Jan 1, 2025, and T2 is Jan 1, 1970, a 24-hour TTL results in an eTTL of 55 years and 24 hours.
  • Attack Method 2: Fixing T1 in the Future: Generating a license request with T1 far in the future (e.g., Jan 1, 2125) and loading it in the present (T2 = Jan 1, 2025) results in an expiration time of T3 = Jan 2, 2125, yielding an eTTL of 100 years and 24 hours.
  • Fixing time indefinitely (e.g., ti = T2 for all i) caused video buffering issues, as Firefox uses the same time functions. A selective time-fixing approach was needed.

Demo / Proof of Concept

The Narrowbeer attack is a practical replay mechanism built upon the insights from the empirical investigation. It distinguishes between two types of attackers: a Harvester (a legitimate subscriber) who collects licenses, and Consumers (non-subscribers) who replay them. Both use the same hooking methodology to control time and randomness.

Settings

The attack was implemented and validated on Debian 12 (Linux) and Windows 11, using Firefox esr-128 as the EME User-Agent and Widevine CDM version 4.10.2710.0. The authors noted that this specific Widevine version has since been deprecated and patched by Google, but the underlying vulnerability in time enforcement might still exist.

Overcoming Technical Challenges

To ensure the attack's broad applicability, two key challenges identified in the empirical investigation were addressed:

  • Time Control: Indefinitely fixing time causes video buffering issues. Narrowbeer implements selective time fixing: time is fixed to a value T during license request generation until the 82-byte RSA-PSS signature salt is obtained (identifying completion of critical random value generation). After this, the time returned by hooked functions progresses normally (T + i seconds). This ensures the fixed request timestamp for the license server while allowing normal video playback. The Harvester optionally sets this T far in the future (e.g., year 2286) to create a "never-expiring" license.
  • Randomness Control: The issue of the unfixable RSA-OAEP seed (due to Intel RDRAND instructions in BoringSSL) was critical. The authors dynamically modified two bytes in the Widevine binary's memory at runtime to ensure the RDRAND branch in BoringSSL is never taken. This forces BoringSSL to fall back to OS system calls for randomness, which can then be intercepted and controlled by Narrowbeer's hooks. While this "weakens" the threat model by dynamically attacking Widevine's memory, it makes the attack portable across Linux and Windows without breaking complex obfuscation or memory integrity protections.

The Narrowbeer Attack Workflow

The attack proceeds in three steps, as depicted in Figure 3 of the paper:

  1. First Step: Collect (Encrypted) Media Tracks: The Harvester (subscriber) accesses a streaming service and retrieves the manifest file (e.g., MPD file for DASH streaming). This file contains metadata about the content, including URLs for encrypted media tracks, which are publicly accessible. The URL of this manifest is collected for sharing.
  2. Second Step: Harvest License Responses: The Harvester uses Narrowbeer, which attaches to Firefox (via ptrace on Linux or SeDebugPrivilege with OpenProcess on Windows). Narrowbeer intercepts system calls to fix all necessary random values and the request timestamp (T1) to a chosen, consistent value (e.g., year 2286 for indefinite expiration). The Harvester then requests a license for the desired content. The license server, unaware of the manipulation, issues a valid license response. Narrowbeer intercepts this response and stores it, typically as a small (few kilobytes) JSON file. This "rogue" but valid license response is then ready to be shared.
  3. Third Step: Replay License Responses for Free: A Consumer (non-subscriber) receives the shared JSON file (containing the manifest URL and the harvested license response) and runs Narrowbeer on their own desktop. They then navigate to a modified version of Shaka Player (an open-source video player by Google) hosted locally. This modified Shaka Player does not contact the license server. Instead, when Widevine generates a license request for the content (after retrieving the manifest), Narrowbeer intervenes. It fixes the time and random values in the Consumer's Widevine CDM to exactly match those used by the Harvester when the license was first generated. The modified Shaka Player then feeds the harvested license response directly to the CDM via UpdateSession. Because the derivation buffers and other critical values match, the CDM successfully loads the license, decrypts the content, and allows playback without any interaction with the content provider's license server or subscription verification.

Validation

The attack was first validated against protected content on the Shaka Player demo website. The researchers successfully:

  • Retrieved the content manifest URL and the license response JSON.
  • Replayed this JSON on a separate desktop using Narrowbeer and the modified Shaka Player, playing the content without contacting the license server.

Beyond the demo, Narrowbeer was successfully evaluated against two premium streaming services with clear disclosure policies: Netflix and Prime Video. The attack allowed the researchers to watch content on both platforms without an active subscription, demonstrating its real-world applicability.

Defensive Implications

The Narrowbeer attack exposes fundamental limitations of software-only DRM implementations like Widevine, especially in desktop environments where an attacker has full control over their device. The authors argue that merely increasing the complexity of software protections (e.g., anti-ptrace mechanisms, more complex randomness generation) only delays attackers, as they do not address the root cause: the reliance on manipulable external system resources.

Several potential mitigations are discussed, along with their challenges:

  • Kernel Drivers: Implementing Widevine as a kernel driver might prevent user-land hooking of libraries. However, this could simply shift attacks to the kernel space, which is still vulnerable, as seen with anti-cheat solutions.
  • Internal Random Generators: Widevine could implement its own random number generator without relying on standard OS system calls (getrandom/RtlGenRandom). While this removes the risk of system call interception, it remains vulnerable to reverse engineering and dynamic patching, as demonstrated by the BoringSSL RDRAND bypass in Narrowbeer. Ensuring sufficient entropy for cryptographic operations in a software-only internal generator is also a challenge.
  • Specialized CPU Instructions: Leveraging instructions like Intel RDRAND can make randomness generation harder to intercept. However, this limits portability, as not all CPUs support such instructions, forcing a fallback to OS-dependent solutions (as seen with BoringSSL's design).
  • Hardware-Backed CDMs (TEEs): The most robust mitigation involves using Trusted Execution Environments (TEEs), such as Widevine L1 (for Android) or ARM TrustZone. In a TEE, critical operations like license request generation and random value generation are isolated and protected from the main system. The problem is that hardware CDMs are not widely available or deployed on desktop machines (Intel SGX is deprecated). Pushing L1 CDM to ARM-based desktops could be a future direction.

The authors conclude that Widevine's strong emphasis on portability (being cross-platform and cross-browser) inherently conflicts with the robust security required to resist attacks from a fully controlled host environment. Relying on OS-specific features or hardware extensions would compromise this portability.

Responsible Disclosure and Patching

The researchers responsibly disclosed their findings to Google (Widevine), Netflix, and Prime Video. All parties acknowledged the vulnerability.

  • Prime Video attempted a server-side patch by rejecting license requests with timestamps exceeding three days. However, this was ineffective against Narrowbeer, as the Consumer does not contact the license server after the Harvester has obtained the license.
  • Netflix initially dismissed the issue but later engaged to facilitate communication with Widevine.
  • Google/Widevine eventually released a patch in August 2024 (CDM version 4.10.2830.0), which deprecated the vulnerable version three months later. The patch uses an additional internal source of randomness to break the replay attack. However, the authors, being excluded from the patching process, express concern that this new source of randomness could also be bypassed once its internals are identified and controlled. Furthermore, the vulnerability allowing for never-expiring licenses (by manipulating T1 and T2) reportedly still remains exploitable in the patched version. Google did not issue a public statement, which the authors view as detrimental to the DRM ecosystem's security-by-obscurity approach.

Key Takeaways

  • Software-only DRMs are inherently brittle on controlled desktops: Widevine's software-based CDM, while portable, is fundamentally vulnerable when an attacker controls the underlying operating system and browser environment.
  • Time and randomness are critical, manipulable attack vectors: Widevine's reliance on the OS for time and random number generation creates exploitable weaknesses, even if its internal cryptographic mechanisms are robust.
  • Narrowbeer enables never-expiring, shareable licenses: By selectively fixing system time and randomness, the attack allows legitimate users to generate licenses with effectively infinite lifetimes, which can then be shared and reused by unauthorized users on different devices.
  • Replay attacks bypass subscription models and content provider infrastructure: Narrowbeer transforms content providers' CDN into a piracy distribution network, as only small license files (kilobytes) need to be shared, rather than large video files.
  • The "T2 < T1" flaw allows indefinite license extension: Widevine's failure to enforce that a license's load time (T2) must be after its request time (T1) is a critical design flaw enabling licenses to be used for decades.
  • Hardware-backed solutions are the strongest defense: True resistance against such system-level attacks likely requires hardware-backed CDMs (e.g., TEEs), which isolate critical operations from the host system, but are currently not widely available or deployed on desktop platforms.

About the Speaker(s)

The research paper "Narrowbeer: A Practical Replay Attack Against the Widevine DRM" was authored by Florian Roudot and Mohamed Sabt. Both researchers are affiliated with IRISA, a research institute in computer science and random systems, and are associated with Univ Rennes and CNRS (Centre national de la recherche scientifique). Their work contributes to the field of software security, specifically focusing on the vulnerabilities and practical attacks against widely deployed Digital Rights Management systems.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This is the kind of research that makes vendors deeply uncomfortable — not because it breaks fancy crypto, but because it exposes a design assumption so obvious in hindsight that you wonder how it shipped. The T2 < T1 flaw is embarrassing for Widevine, and the replay attack is elegant, practical, and devastating to the entire license-based DRM model on desktop.

Heather Calloway (CISO) — STRONG ACCEPT

Consequential research that demonstrates Widevine's desktop DRM can be bypassed through system-level manipulation of time and randomness, enabling license replay and sharing without subscription. Every CISO with streaming content licensing exposure, media partnerships, or content protection obligations should understand this exists.

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)