Disclosed Chromium Security Bugs
←Back to DashboardORT DML EP: heap-buffer-overflow in CreateCpuResource via int4/uint4 constants
$10,000
7/25/2026
WebML Double-Free Via XNNPACK LUT-Fusion
$43,000
7/25/2026
V8 Sandbox Bypass: double-free in HandleScope::Extend via concurrent JS stack printing from MainMarkingVisitor and ConcurrentMarkingVisitor
$5,000
7/24/2026
XNNPACK Workspace Size Overflow — Heap Buffer Overflow from WebNN
$42,000
7/24/2026
V8 Sandbox Bypass:TypedArray.prototype.set ElementsKind TOCTOU
$5,000
7/23/2026
Use-after-free in DevToolsRendererChannel::ForceDetachWorkerSessions via duplicate ChildTargetCreated for dedicated workers
$26,000
7/23/2026
Heap UAF in Blink OffscreenCanvas
$7,000
7/23/2026
V8 Sandbox Bypass: Gin FunctionTemplateInfo EPT Type Confusion via Shared ExternalPointerTag
$5,000
7/23/2026
V8 Sandbox Escape: CopyElementsHandleSlow→SetImpl missing SBXCHECK — OOB Write 192GB past guard via getter re-entrancy (race-free, deterministic)
$5,000
7/23/2026
V8: Incorrect Address Computation in Int64LoweringReducer via IncreaseOffset element_scale Mishandling
$8,000
7/23/2026