Jonathan Metzman Profile
Jonathan Metzman

@metzmanj

Followers
2K
Following
5K
Media
13
Statuses
942

I do fuzzing on Google's Open Source Security Team. I work on OSS-Fuzz/ClusterFuzz/FuzzBench. Speaking on behalf of myself, not my employer.

Joined January 2019
Don't wanna be here? Send us removal request.
@metzmanj
Jonathan Metzman
2 years
Check out our work on using LLMs to generate fuzz targets in OSS-Fuzz:.
Tweet media one
3
30
132
@metzmanj
Jonathan Metzman
1 month
RT @ForrestPKnight: you're not allowed to write comments in your code anymore, because if you do everyone will just think it's ai generated.
0
522
0
@metzmanj
Jonathan Metzman
4 months
RT @robertswiecki: honggfuzz alive and kicking. stack based buffer overflow in libxml2 -
0
19
0
@metzmanj
Jonathan Metzman
5 months
RT @Davkorcz: Auto generating #fuzzing harnesses by way of program analysis and #LLMs! New blog post "Minimal LLM-based fuzz harness genera….
0
21
0
@metzmanj
Jonathan Metzman
5 months
RT @mboehme_: #FUZZING'25 CALL FOR PAPERS.──────.✨ New OC members: @RuijieMeng (NUS) + Rohan Padhye (@moarbugs; CMU). ✨ New paper type: Fuz….
0
19
0
@metzmanj
Jonathan Metzman
5 months
RT @mboehme_: ICLR'25 Spotlight 🤩 (5% of accepted papers) -- for a topic we've just been nerding out on. Congrats Seongmin! 🎉. 📝 https://t….
0
5
0
@metzmanj
Jonathan Metzman
6 months
The original link I posted for the OSS-Fuzz PhD internship was wrong, sorry to folks who applied to the research intern position. Please re-apply to the one below. The correct one is for the SWE intern position. 🤦.
@metzmanj
Jonathan Metzman
6 months
0
5
14
@metzmanj
Jonathan Metzman
6 months
0
0
4
@metzmanj
Jonathan Metzman
6 months
RT @mboehme_: If I was still a PhD, I would definitely take this opportunity. So much opportunity for real impact!.
0
4
0
@metzmanj
Jonathan Metzman
6 months
If you've already applied, DM me to setup a chat.
0
0
3
@metzmanj
Jonathan Metzman
6 months
The OSS-Fuzz team is hiring a PhD intern for this summer. Come join us and build the future of fuzzing. Link in next tweet in thread. RTs appreciated!.
2
32
88
@metzmanj
Jonathan Metzman
7 months
RT @clintgibler: 📚 tl;dr sec 258. 🤖 Google's AI-powered Fuzzing @halbecaf, @metzmanj.☁️ What Hackers know about your AWS Account @dagrz.🔬 F….
0
7
0
@metzmanj
Jonathan Metzman
7 months
RT @l33d0hyun: My LLM analyzed a vulnerability in a Linux library and even created a PoC! This is expected to be used in Browser's Sandbox….
0
78
0
@metzmanj
Jonathan Metzman
7 months
RT @clintgibler: 🤖 The latest in LLM-powered fuzzing from Google. 26 new vulns so far, 1 in OpenSSL. The LLM can draft a fuzz target, fix c….
0
17
0
@metzmanj
Jonathan Metzman
8 months
LLMs are just a special case of fuzzing btw.
@cloneofsimo
Simo Ryu
8 months
"its actually just special case of [INSERT_YOUR_WORK/FIELD_HERE]. ". RL people : thats actually just RL btw.Diffusion people: thats actually diffusion btw.Autoregressive people: thats actually next token prediction btw.Transformer people: attention literally all you need btw.
1
0
3
@metzmanj
Jonathan Metzman
8 months
0
3
14
@metzmanj
Jonathan Metzman
8 months
We published more details about our LLM-based fuzz target generator, which found CVE-2024-9143 in OpenSSL
Tweet media one
1
20
123
@metzmanj
Jonathan Metzman
8 months
RT @argvee: On the heels of @Google’s ‘Big Sleep’ AI discovery of a real-world vulnerability, our OSS-Fuzz team identified and reported 26….
0
30
0
@metzmanj
Jonathan Metzman
8 months
RT @moyix: XBOW found a critical auth bypass (CVE-2024-50334) in a widely-used open-source Q&A site, fully autonomously! @nicowaisman and I….
0
19
0
@metzmanj
Jonathan Metzman
8 months
RT @domenuk: Project Zero blog:.LLMs find 0days now! 👀. And: our fuzzer setup did *not* reproduce it! https://t.c….
0
150
0
@metzmanj
Jonathan Metzman
9 months
Our LLM work has found an out-of-bounds read in OpenSSL!
Tweet media one
@halbecaf
Oliver Chang
9 months
CVE-2024-9143 ( was disclosed recently, which was found by OSS-Fuzz-Gen! This is a pretty proud example of our team showing the promise of leveraging LLMs enable more fuzzing coverage.
3
46
215