Disclosed Chromium Security Bugs
←Back to DashboardMissing validation in BeginNavigation allows Private State Token corruption
$0
7/29/2026
ANGLE: missing setPixelPackBuffer(nullptr) in norm16 readback workaround causes GPU process crash via WebGL PBO type confusion
$5,000
7/29/2026
Use-After-Free in AllocateSctpSids via DCEP OPEN Message Failure Leads to Renderer Crash
$11,000
7/29/2026
Privacy and rate-limit bypass in Private State Tokens via custom_key_commitment
$0
7/29/2026
Arbitrary Memory Read and Write in ANGLE GL Backend via PBO Desync
$97,000
7/29/2026
GPU process arbitrary address read via unvalidated client pointer in passthrough `CompressedTexImage3D` / `CompressedTexSubImage3D` handlers
$5,000
7/29/2026
WebGPU `setBindGroup()`: renderer crash and bounds-check bypass via ResizableArrayBuffer shrink during argument coercion (PassAsSpan TOCTOU)
$0
7/29/2026
Potential Use-After-Free in bssl-tls during Certificate Parsing due to dangling pool pointer
$0
7/29/2026
Potential UAF and Double-Free in libwebm Segment::WriteFramesLessThan
$0
7/29/2026
Potential Use-After-Free in js_injection::JsBinding due to lazy sweeping of Mojo receiver
$0
7/29/2026