Book Cover

Fuzzing Android: Finding Vulnerabilities in Userspace and the Kernel

Contributor(s): Zawawy, Hamzeh (Author), Rodionov, Eugene (Author), Xing, Xuan (Author), Alder, Kris (Author), Barker, Cory (Author), Moreland, Steven (Author)

ISBN: 9781718505292

Publisher: No Starch Press

Binding Types:

$69.99
$82.94 (Final Price)
$81.74 (100+ copies: $80.99)
List/retail price:
$69.99
- +
Buy

Pub Date: November 10, 2026

Lexile Code: 0000

Target Age Group: NA to NA

Physical Info: 0.00" H x 0.00" L x 0.00" W ( 0.00 lbs) 216 pages

Descriptions, Reviews, etc.

Description: The operational playbook for fuzzing Android, from Binder services to the Linux kernel, by Google's Android Security Team.

Android is three billion devices of hardened, audited, relentlessly defended code, and fuzzing brings it down anyway. The method is brutally simple: Bury the system in malformed input, and wait for the rare case that cracks something open. Every crash is a lead, and behind it is usually a way in.

The Google engineers who authored this book do that for a living. They've fuzzed Android's Binder IPC, the Pixel modem, the GPU drivers, and the kernel, uncovering root-level vulnerabilities the architecture was supposed to keep out of reach, and now they show you how they work.

Most fuzzing books stop at the concept; this one runs the campaign. You'll learn how to:

  • Build reproducible fuzzing environments across emulators and physical devices
  • Target Android's Binder IPC, native system services, GPU drivers, and kernel interfaces
  • Instrument code for coverage using AFL++ or libFuzzer and extend Syzkaller to reach new kernel drivers
  • Triage, reproduce, and investigate crashes to uncover real vulnerabilities
  • Develop the judgment to choose high- value targets and bypass runtime checks when appropriate.

Whether you're a security researcher, an OEM security engineer, or a bug bounty hunter, Fuzzing Android is your operational playbook for finding vulnerabilities in the world's largest mobile platform.

Covers: Android 17+ and is backward compatible with earlier AOSP releases.

Requires: A physical Android device or emulator (Cuttlefish); all required tools are open source.

Product successfully added to cart!