Android Goes All-in on Fuzzing
ID: a98c851d-9f22-5823-9674-c06259440a8a
STIX ID: report--a98c851d-9f22-5823-9674-c06259440a8a
Feed Name: Google Online Security Blog
Android Security describes its end-to-end continuous fuzzing infrastructure for AOSP, covering fuzzer integration with Soong, large-scale execution via ClusterFuzz on devices and emulators, coverage metrics (edge and line), automated triage aligned to severity guidelines, and prioritization strategies. The post shares challenges (e.g., low execs/sec, targeting the wrong code), criteria for selecting high-impact fuzz targets, examples of vulnerabilities uncovered (e.g., CVE-2022-20473, CVE-2023-21041), and invites external contributors to submit fuzzers and participate in the Android VRP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
