Using Chrome's accessibility APIs to find security bugs
ID: dc34009c-f514-5208-8aac-f1b48679a4f6
STIX ID: report--dc34009c-f514-5208-8aac-f1b48679a4f6
Feed Name: Google Online Security Blog
Google Chrome’s security team describes a new approach to fuzzing the browser’s UI by interacting with the accessibility tree, combining coverage-guided fuzzing, InProcessFuzzer, and Centipede to explore complex UI paths and produce stable, reproducible test cases. The post details challenges like stateful UI interactions, noisy coverage, and control identification, and introduces a custom mutator to improve effectiveness. Early runs have only found a few potential issues in accessibility code, with broader UI coverage and results still pending.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
