In the docs directory there is a guide to fuzzing. On the plus side, from my initial read, it looks like most of the important stuff has fuzzing harnesses already which means the code should be free of most low hanging security bugs. It also means that with the harnesses already in place, it will be easy for outsiders to just throw a ton of compute at it and possibly find some of the deeper issues.

You mean, more tons of computing than Apple can afford?

You mean, more tons of computing than Apple has already thrown at the problem?

