Jonathan Metzman

Fuzzing on Google's Open Source Security Team. I work on ClusterFuzzLite/FuzzBench/OSS-Fuzz/ClusterFuzz. Speaking on behalf of myself, not my employer.

Jonathan Metzmanmetzman@infosec.exchange
2025-01-15

The OSS-Fuzz team is hiring a PhD intern for this summer. Come join us and build something interesting that will have immediate impact on 1000+ open source projects. google.com/about/careers/appli

Jonathan Metzmanmetzman@infosec.exchange
2024-11-21

We published more details about our LLM-based fuzz target generator, which found CVE-2024-9143 in OpenSSL
security.googleblog.com/2024/1

Jonathan Metzmanmetzman@infosec.exchange
2024-06-25

Some teammates and I wrote a blog post on some ideas for AIxCC as we've been helping out a little.

I'm sure everyone will be surprised that it involves fuzzing!
security.googleblog.com/2024/0

Jonathan Metzmanmetzman@infosec.exchange
2023-08-16

Check out our work on using LLMs to generate fuzz targets in OSS-Fuzz:
security.googleblog.com/2023/0
#fuzzing

Jonathan Metzmanmetzman@infosec.exchange
2023-02-09

@lucasgonze Happy to. Sent you an email!

Jonathan Metzmanmetzman@infosec.exchange
2023-02-01

We published a blog post on some updates we have for OSS-Fuzz rewards: security.googleblog.com/2023/0

Jonathan Metzmanmetzman@infosec.exchange
2023-01-20

Deadline to express interest in our fuzzing competition is today. sbft23.github.io/tools/fuzzing just apply if youre in doubt!

Jonathan Metzmanmetzman@infosec.exchange
2023-01-18

Calling all fuzzing engine developers: Join the SBFT competition for a chance at at least 11K. Deadline for expressing interest is friday sbft23.github.io/tools/fuzzing

Jonathan Metzman boosted:
moyixmoyix
2022-12-19

A while back, @metzman was kind enough to do some fuzzing of the skia graphics library with FTZ enabled. Sadly, it didn't find anything super exciting (just some null derefs, timeouts, and floating point div0s), but you can now see some of them here:
bugs.chromium.org/p/oss-fuzz/i

Jonathan Metzmanmetzman@infosec.exchange
2022-12-06

We're doing the monthly fuzzing zoom at 1:30 PM EST zoom.us/j/99960722134?pwd=ZzZq join us!
#fuzzing

Jonathan Metzmanmetzman@infosec.exchange
2022-11-17

@dmnk @aflplusplus Nice. This has been a dream feature of mine for a while!

Jonathan Metzmanmetzman@infosec.exchange
2022-11-15

Trying to fuzz ClusterFuzzLite using ClusterFuzzLite 😏​
github.com/google/oss-fuzz/pul

turtles all the way down
Jonathan Metzmanmetzman@infosec.exchange
2022-11-12

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst