Disclosed Chromium Security Bugs
←Back to Dashboard[Pwn2Own 2024] enum cache corruption + v8 heap sbx (umbrella bug)
$0
1/1/1970
Sandboxify `Managed` Objects
$0
1/1/1970
Integer overflow in img_alloc_helper of libaom
$0
1/1/1970
V8 Sandbox Bypass: wrapper and call target mismatch in wasm
$5,000
1/1/1970
V8 Sandbox Bypass: stack corruption due to parameter count mismatch
$0
1/1/1970
V8 Sandbox Bypass: Interpreted Function Argument Mismatch
$0
1/1/1970
V8 sandbox violation if SFI::formal_parameter_count doesn't match the parameter count of a function's code
$0
1/1/1970
V8 Sandbox Bypass: control-flow hijacking via WASM Table Indirect call
$5,000
1/1/1970
V8 Sandbox Bypass: AAR/W via generic JSToWasmWrapper type sbxcheck() bypass
$5,000
1/1/1970
chrome://blob-internals has a loose CSP
$0
1/1/1970