Glossary · Term

fuzzing

← all terms

Definition

Plain language

Throwing huge amounts of random or malformed input at a program to see what makes it crash.

As stated in the literature

An automated testing technique that feeds randomized or mutated inputs to a target to surface crashes and vulnerabilities; weak at finding bugs requiring precise structured inputs or specific thread interleavings.

Also called: fuzzer, fuzzers, fuzz

Why it matters: It uncovers crashes and security holes automatically, though it struggles with bugs that need very specific, well-structured inputs to trigger.

For example, a tool feeds a photo app thousands of garbled image files in a row to see which one makes it crash.

Heard on the show

“… notably, the libpng bugs require very specific PNG chunk-type and bit-depth combinations that random fuzzing essentially never hits. …”
Episode 014 — Why a Constrained Pipeline Beat a Full Coding Agent at Finding Bugs 30-to-1

Related concepts

Related terms