What does 100% coverage for VxWorks mean, and why is it important for embedded systems security?

In this RunSafe Security Minute, CTO Shane Fry explains  how achieving 100% coverage for VxWorks removes the attacker’s ability to use ROP gadgets and prevents memory-corruption exploits in embedded systems.

What does 100% coverage for VxWorks mean, and why is it important for embedded systems security?

What “100% coverage” for VxWorks Means — and Why It Stops Exploits

In this RunSafe Security Minute, Shane Fry, RunSafe’s CTO, answers a critical question for embedded systems security: what does “100% coverage” for VxWorks actually mean, and why should teams care? 

Historically, defenses focused on user-space code and application DKMs, but for many VxWorks systems the majority of the exploitable attack surface lives in the kernel. RunSafe pushed protections earlier in the boot and extended randomization so it covers both kernel and application code. The result: RunSafe’s protections eliminate essentially all usable ROP (return-oriented programming) gadgets an attacker would rely on. 

Even if an attacker can write over memory or drop code on the stack, they can’t predict where code lives, so memory-corruption techniques fail. This approach makes VxWorks systems far more resilient to real-world exploitation with minimal developer disruption.

CRA Readiness: Build an SBOM You Can Act On

CRA Readiness: Build an SBOM You Can Act On

Under the Cyber Resilience Act, having an SBOM is only the beginning. Manufacturers need to know exactly what software is in each product release and be able to quickly determine which products are affected when a new vulnerability emerges. For embedded software, that...

read more
Operational Software Assurance

Operational Software Assurance

Security Cannot Stop When Software Ships Critical software can remain deployed for years or even decades. During that time, new vulnerabilities emerge, threats evolve, and AI is accelerating both vulnerability discovery and exploit development. But patching, testing,...

read more
6 Steps to CRA Readiness

6 Steps to CRA Readiness

The EU Cyber Resilience Act (CRA) is reshaping how connected and embedded products must be secured, maintained, and supported. Is your organization ready? Watch this short video to learn six practical steps that can help product manufacturers prepare: Test your...

read more