Skip to main navigation Skip to search Skip to main content

ApkFuzz: Search-Based Fuzzing for Android APK Vulnerability Discovery

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

While most work focuses on executable code, AndroidManifest.xml, serves as the primary entry point for application metadata and permission logic. Yet, it is often overlooked, making it a high-trust, low-scrutiny attack surface. We present ApkFuzz, an AFL-based fuzzer with bit-level mutations targeting the encoded region of AndroidManifest.xml in the APK file. We have identified 9 issues that cause crashes and enable Denial-of-Service (DoS) attacks in core tools, including Google’s apksigner and the widely used research tool DroidBot.

Original languageEnglish
Title of host publicationSearch-Based Software Engineering - 18th International Symposium, SSBSE 2026, Proceedings
EditorsWesley K.G. Assunção, Mijung Kim, Ali Ouni
PublisherSpringer Science and Business Media Deutschland GmbH
Pages135-141
Number of pages7
ISBN (Print)9783032306982
DOIs
StatePublished - 2027
Event18th International Symposium on Search-Based Software Engineering, SSBSE 2026 - Montreal, Canada
Duration: 5 Jul 20266 Jul 2026

Publication series

NameLecture Notes in Computer Science
Volume16699 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th International Symposium on Search-Based Software Engineering, SSBSE 2026
Country/TerritoryCanada
CityMontreal
Period5/07/266/07/26

Keywords

  • AFL
  • Android
  • APK
  • DoS
  • Fuzzing
  • SBSE

Fingerprint

Dive into the research topics of 'ApkFuzz: Search-Based Fuzzing for Android APK Vulnerability Discovery'. Together they form a unique fingerprint.

Cite this