Disclosed Chromium Security Bugs

V8 Sandbox Bypass: JSPI suspender EPT not cleared in exception-unwind path

#501147587Reporter: qq...@calif.io
$5,000
7/23/2026

Security: double-free in blink::WebRtcVideoFrameAdapter::SharedResources::ScaleAndMapFrameAsync

#494823867Reporter: zh...@gmail.com
$11,000
7/22/2026

Type confusion in BuildCheckSmi constant folding in V8/Maglev

#500880819Reporter: qq...@calif.io
$55,000
7/22/2026

TFLite castInt4ToFloat heap-buffer-overflow (OOB Write) via WebNN dequantizeLinear

#498063923Reporter: to...@gmail.com
$33,000
7/22/2026

heap-buffer-overflow in Dawn BufferGL::MapAtCreationImpl

#500774812Reporter: ki...@gmail.com
$33,000
7/19/2026

Reentrant vector mutation during FrameSink invalidation causes heap use-after-free in Viz process

#493955227Reporter: je...@gmail.com
$16,000
7/18/2026

Debug check failed: i < this ->context_local_count() (0 vs. 0). in v8

#499752800Reporter: sw...@gmail.com
$8,000
7/18/2026

V8 sandbox bypass: WasmDispatchTable swapping lead to use of not fully initialized WasmTrustedInstanceData

#498095290Reporter: pv...@gmail.com
$20,000
7/18/2026

heap-use-after-free in dawn::native::vulkan::BindGroupLayout::GetOrCreateSpecializedHandle

#500609038Reporter: ki...@gmail.com
$11,000
7/18/2026

VP9 alpha plane use-after-free via show_existing_frame reuse of FrameBufferPool storage

#500066234Reporter: je...@gmail.com
$8,000
7/17/2026
Showing 31-40 of 1144 bugs
1...345...115