@inproceedings{4f2e7dab397041cd8a7197b86df2eaf6,
title = "ApkFuzz: Search-Based Fuzzing for Android APK Vulnerability Discovery",
abstract = "While most work focuses on executable code, AndroidManifest.xml, serves as the primary entry point for application metadata and permission logic. Yet, it is often overlooked, making it a high-trust, low-scrutiny attack surface. We present ApkFuzz, an AFL-based fuzzer with bit-level mutations targeting the encoded region of AndroidManifest.xml in the APK file. We have identified 9 issues that cause crashes and enable Denial-of-Service (DoS) attacks in core tools, including Google{\textquoteright}s apksigner and the widely used research tool DroidBot.",
keywords = "AFL, Android, APK, DoS, Fuzzing, SBSE",
author = "Karine Even-Mendoza and Aidan Dakhama and Harel Berger",
note = "Publisher Copyright: {\textcopyright} The Author(s), under exclusive license to Springer Nature Switzerland AG 2027.; 18th International Symposium on Search-Based Software Engineering, SSBSE 2026 ; Conference date: 05-07-2026 Through 06-07-2026",
year = "2027",
doi = "10.1007/978-3-032-30699-9\_13",
language = "אנגלית",
isbn = "9783032306982",
series = "Lecture Notes in Computer Science",
publisher = "Springer Science and Business Media Deutschland GmbH",
pages = "135--141",
editor = "Assun{\c c}{\~a}o, \{Wesley K.G.\} and Mijung Kim and Ali Ouni",
booktitle = "Search-Based Software Engineering - 18th International Symposium, SSBSE 2026, Proceedings",
address = "גרמניה",
}