logo

Android Goes All-in on Fuzzing

ID: a98c851d-9f22-5823-9674-c06259440a8a

STIX ID: report--a98c851d-9f22-5823-9674-c06259440a8a

Feed Name: Google Online Security Blog

Date Published: 2023-08-29

Date Updated: 2026-04-27

Author: Edward Fernandez

...
...

Android Security describes its end-to-end continuous fuzzing infrastructure for AOSP, covering fuzzer integration with Soong, large-scale execution via ClusterFuzz on devices and emulators, coverage metrics (edge and line), automated triage aligned to severity guidelines, and prioritization strategies. The post shares challenges (e.g., low execs/sec, targeting the wrong code), criteria for selecting high-impact fuzz targets, examples of vulnerabilities uncovered (e.g., CVE-2022-20473, CVE-2023-21041), and invites external contributors to submit fuzzers and participate in the Android VRP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.