logo

AI-Powered Fuzzing: Breaking the Bug Hunting Barrier

ID: f6646e28-6b44-556b-8274-c650676e99e6

STIX ID: report--f6646e28-6b44-556b-8274-c650676e99e6

Feed Name: Google Online Security Blog

Date Published: 2023-08-16

Date Updated: 2026-04-27

Author: Kimberly Samra

...
...

Google describes leveraging LLMs to automatically generate fuzz targets within OSS-Fuzz, increasing code coverage across open-source projects by 1.5–31% (e.g., tinyxml2 from 38% to 69%) and rediscovering OpenSSL CVE-2022-3602 in previously unfuzzed code. They plan to open source their evaluation framework, fully integrate continuous LLM-generated fuzzing into OSS-Fuzz, extend support beyond C/C++ to languages like Python and Java, and automate project onboarding to scale vulnerability detection for 1,000+ projects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.