Google's OSS-Fuzz with AI Finds Critical OpenSSL Bug After Two Decades
Google's AI-powered OSS-Fuzz tool has uncovered 26 previously unknown vulnerabilities in open-source software, including a critical flaw in OpenSSL (CVE-2024-9143) that existed undetected for 20 years. Leveraging large language models (LLMs) like Vertex AI Codey and OpenAI's models, OSS-Fuzz automates the creation and improvement of fuzz targets, significantly enhancing its bug-finding capabilities.
The AI-driven enhancements have improved code coverage for 272 C/C++ projects, identifying vulnerabilities such as out-of-bound reads and writes. Google plans to further automate this system, aiming to autonomously identify, report, and triage bugs in open-source projects
https://thehackernews.com/2024/11/googles-ai-powered-oss-fuzz-tool-finds.html
Comments
Post a Comment