Google's AI-powered fuzzing tool, OSS-Fuzz, has discovered 26 vulnerabilities in various open-source code repositories including a medium-severity flaw in OpenSSL.
One of the vulnerabilities found in OpenSSL has the potential to cause remote code execution (RCE) attacks.
These discoveries mark a significant milestone in automated vulnerability finding using AI-generated and enhanced fuzz targets.
Google's improvements in generating relevant context and emulating a typical developer's workflow have contributed to higher quality and greater number of correct fuzz targets.