Disclosed Chromium Security Bugs

CHECK failure: isolate_->IsOnCentralStack()

#422811244Reporter: 24...@project.gserviceaccount.com
$0
9/14/2025

DCHECK failure in obj.is_null() || IsSmi(*obj) || !IsTheHole(*obj) in api-inl.h

#422099361Reporter: 24...@project.gserviceaccount.com
$0
9/14/2025

opencv:core_fuzzer: Heap-buffer-overflow in png_combine_row

#444754937Reporter: 87...@developer.gserviceaccount.com
$0
9/13/2025

DCHECK failure in IsHeapNumber(*number) implies Cast(number)->value_as_bits() != kUnde

#422811228Reporter: 24...@project.gserviceaccount.com
$0
9/13/2025

UAF in StackSampler

#421471016Reporter: ha...@gmail.com
$4,000
9/13/2025

CHECK failure: (value & uint64_t{ADDRESS}) != unexpected || (value & uint64_t{ADDRESS}) == uint

#416907157Reporter: 24...@project.gserviceaccount.com
$0
9/13/2025

envoy:evaluator_fuzz_test: Use-after-poison in std::__1::basic_string, std::__1::allocator

#435894354Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025

spirv-cross:parser_fuzzer: Crash in spirv_cross::SPIRBlock* spirv_cross::ObjectPool::allocat

#427814449Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025

vlc:vlc-demux-dec-libfuzzer-mp4: Heap-buffer-overflow in FragPrepareChunk

#437694938Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025

vlc:vlc-demux-dec-libfuzzer-h265: Heap-buffer-overflow in cc_storage_append

#437855564Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025
Showing 91-100 of 8577 bugs
1...91011...858