Disclosed Chromium Security Bugs
←Back to DashboardV8 sandbox bypass: reuse unpublished WasmDispatchTable lead to reproduce of 483220222
$20,000
7/30/2026
[Linux] Cross-Thread Use-After-Free in FontLoader::openStream via Non-Owning MappedFontFile Cache
$11,000
7/30/2026
CanvasRenderingContext2D::drawFocusIfNeeded dangling `Path` use-after-free
$7,000
7/30/2026
Intl.Collator/PluralRules/DateTimeFormat still use Managed<>->raw() not ->get()
$5,000
7/30/2026
Renderer-to-GPU sandbox escape via Skia SPIR-V injection
$25,000
7/30/2026
ANGLE: missing setPixelPackBuffer(nullptr) in norm16 readback workaround causes GPU process crash via WebGL PBO type confusion
$5,000
7/29/2026
Use-After-Free in AllocateSctpSids via DCEP OPEN Message Failure Leads to Renderer Crash
$11,000
7/29/2026
Arbitrary Memory Read and Write in ANGLE GL Backend via PBO Desync
$97,000
7/29/2026
GPU process arbitrary address read via unvalidated client pointer in passthrough `CompressedTexImage3D` / `CompressedTexSubImage3D` handlers
$5,000
7/29/2026
Stack out-of-bounds write in CreateBufferFromHandle: unchecked DMA-BUF plane count from compromised renderer overflows fixed-size gbm_import_fd_modifier_data arrays in GPU process.
$11,000
7/25/2026