Disclosed Chromium Security Bugs
←Back to DashboardFenced frame `_unfencedTop` navigation leaks `initiator_origin` to destination via `Sec-Fetch-Site`
$3,000
8/13/2026
VerifyInitiatorOrigin() skips HostsOrigin() process lock check for opaque origins in error documents and MHTML subframes
$2,000
8/13/2026
Previous page executes JS after navigation, allowing history.back() tab hijack
$2,000
8/13/2026
Popup window tab doesn't show the origin correctly
$1,000
8/13/2026
Site Isolation bypass via error page precursors and sandboxed srcdoc frames
$0
8/13/2026
Parser differential in experimental Rust XML lexer via chunk boundaries
$0
8/13/2026
Info leak of global UMA data via metricsPrivate.getHistogram in chrome-untrusted://
$0
8/13/2026
Potential cross-origin info leak via uninitialized Skia stencil buffer
$0
8/13/2026
Sandbox escape via AppleScript `save` command allowing arbitrary file write
$0
8/13/2026
Compromised renderer can remove other extensions' webRequest listeners via EventRouter IPC
$0
8/13/2026