NASS: Fuzzing All Native Android System Services with Interface Awareness and Coverage

Philipp Mao, Marcel Busch, Mathias Payer

34th USENIX Security Symposium · Day 1

This article details the research presented in the USENIX Security paper "NASS: Fuzzing All Native Android System Services with Interface Awareness and Coverage." The paper introduces NASS, a novel fuzzer designed to uncover critical vulnerabilities in **proprietary native Android system services**. Given the increasing sophistication of Android's security mechanisms, such as stricter app sandboxes and kernel hardening, attackers are shifting their focus to highly privileged user-space components. Native system services, often implemented in C++ and responsible for interacting with hardware, represent a significant and under-explored attack surface, especially those that are closed-source and developed by original equipment manufacturers (OEMs).

AI review

This is exactly the kind of systems security research that moves the field forward. NASS solves a real problem — fuzzing closed-source Android HAL services — with a clever technique (DGIE) that actually works, validated by 12 real bugs including a UAF on Pixel 9. The 96% interface recovery rate against ground truth isn't hand-waving; it's measured.