Disclosed Chromium Security Bugs

I identified that the Chrome browser’s Reading List feature introduces an origin confusion issue by reordering domain names. This behavior can mislead users about the true origin of a website.

#503346647Reporter: ah...@gmail.com
$500
7/30/2026

Use-After-Free in Page::OrdinaryPages() iteration via synchronous Navigation API abort

#502089411Reporter: vm...@google.com
$0
7/30/2026

Info Leak: Missing clipboard sequence check in DataObjectItem::GetAsFile

#501920294Reporter: vm...@google.com
$0
7/30/2026

Autofill preview info leak in appearance: base-select via font side-channel

#501779840Reporter: vm...@google.com
$0
7/30/2026

Path Traversal in enterprise.reportingPrivate.setDeviceData Allows Arbitrary File Deletion

#501467566Reporter: vm...@google.com
$0
7/30/2026

ANGLE Vulkan Out-of-bounds index read via stale index buffer offset

#500530720Reporter: vm...@google.com
$0
7/30/2026

Robust Resource Initialization Bypass via Level Index Confusion in ANGLE

#500161302Reporter: vm...@google.com
$0
7/30/2026

Heap-use-after-free in v8_inspector::InjectedScript::wrapObjectMirror due to context destruction in JS callback

#503553614Reporter: al...@gmail.com
$3,000
7/30/2026

Heap-UAF in RtpSenderBase::DetachTrackAndGetStopTask during SDP rollback

#504194151Reporter: r2...@gmail.com
$0
7/30/2026

Potential LPE via Named Pipe Squatting and Mojo IPCz Handle Confusion in Google Updater

#504104263Reporter: vm...@google.com
$0
7/30/2026
Showing 1301-1310 of 13102 bugs