Rethinking Emulation for Fu(zzi)n(g) and Profit: Near-Native Rehosting for Embedded ARM Firmware

No ratings

Presented at RE//verse 2025 by

Rehosting, the art of running the firmware in a virtualized environment, rather than on the original hardware platform, is the de-facto standard for fuzzing embedded firmware. Off-the-shelf solutions for emulation such as QEMU were not designed with fuzzing in mind, where we want to optimize for as many executions per second as feasible. We showcase near-native rehosting: running embedded firmware as a Linux userspace process on a high-performance system that shares the instruction set family with the targeted device. After discussing the intricacies of lifting and rewriting ARM instructions, we fuzz ARM Cortex-M firmware and show that our framework, SAFIREFUZZ, can provide a 690x throughput increase on average during 24-hour fuzzing campaigns while covering up to 30% more basic blocks.