Disclosed Chromium Security Bugs

Mojo handle double-close / use after close leads to uaf/double free

#496266444Reporter: da...@gmail.com
$5,000
8/4/2026

V8 Sandbox Bypass: Compiler-Eliminated CPT Tag Check

#500771385Reporter: qw...@gmail.com
$20,000
8/4/2026

Missing lifetime check in SpdyStream::IncreaseRecvWindowSize leads to use-after-free in Network Service

#503420443Reporter: je...@gmail.com
$43,000
8/4/2026

D3D10Warp!JITCopyContext::ExecuteResourceCopy memory heap overflow based on Integer overflow in gpu

#480548427Reporter: do...@gmail.com
$17,000
8/4/2026

V8: Turboshaft miscompilation: Operand drop in TryReduceRorInTree allows potential sandbox bypass

#505823721Reporter: or...@gmail.com
$8,000
8/4/2026

Validating Decoder Stale PACK_ALIGNMENT causes GPU Heap OOB Write

#505077859Reporter: ci...@gmail.com
$43,000
8/1/2026

V8 SBX Trap Fuzzing: Container Overflow in src/bigint/bigint.h:163:37

#504663582Reporter: al...@goodmanemail.com
$5,000
8/1/2026

Turbolev: incorrent opcode effect modeling can lead to arbitrary code execution

#503975738Reporter: pj...@gmail.com
$55,000
8/1/2026

Turboshaft: stale `PhiOp` replacement for Wasm arrays causes `array.len` bounds bypass and out-of-bounds array read/write

#505481948Reporter: pj...@gmail.com
$55,000
7/31/2026

UAF in WebViewImpl::Minimize

#492899974Reporter: he...@gmail.com
$11,000
7/31/2026
Showing 1-10 of 1144 bugs