Definition
Plain language
Throwing huge amounts of random or malformed input at a program to see what makes it crash.
As stated in the literature
An automated testing technique that feeds randomized or mutated inputs to a target to surface crashes and vulnerabilities; weak at finding bugs requiring precise structured inputs or specific thread interleavings.
Also called: fuzzer, fuzzers, fuzz
Why it matters: It uncovers crashes and security holes automatically, though it struggles with bugs that need very specific, well-structured inputs to trigger.
For example, a tool feeds a photo app thousands of garbled image files in a row to see which one makes it crash.
Heard on the show
“… notably, the libpng bugs require very specific PNG chunk-type and bit-depth combinations that random fuzzing essentially never hits. …”Episode 014 — Why a Constrained Pipeline Beat a Full Coding Agent at Finding Bugs 30-to-1