the worst part is that testing might give something that is reliable against non-malicious inputs, and then explode given malicious ones. actually, that's not the worst part. the worst part is when nothing seems to occur on a malicious input, but actually rce is occurring
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i....