Disclosed Chromium Security Bugs

Missing validation in BeginNavigation allows Private State Token corruption

#499038510Reporter: vm...@google.com
$0
7/29/2026

ANGLE: missing setPixelPackBuffer(nullptr) in norm16 readback workaround causes GPU process crash via WebGL PBO type confusion

#503768143Reporter: ma...@gmail.com
$5,000
7/29/2026

Use-After-Free in AllocateSctpSids via DCEP OPEN Message Failure Leads to Renderer Crash

#503422316Reporter: je...@gmail.com
$11,000
7/29/2026

Privacy and rate-limit bypass in Private State Tokens via custom_key_commitment

#496286813Reporter: vm...@google.com
$0
7/29/2026

Arbitrary Memory Read and Write in ANGLE GL Backend via PBO Desync

#498904293Reporter: ki...@gmail.com
$97,000
7/29/2026

GPU process arbitrary address read via unvalidated client pointer in passthrough `CompressedTexImage3D` / `CompressedTexSubImage3D` handlers

#495373657Reporter: se...@gmail.com
$5,000
7/29/2026

WebGPU `setBindGroup()`: renderer crash and bounds-check bypass via ResizableArrayBuffer shrink during argument coercion (PassAsSpan TOCTOU)

#497183443Reporter: sw...@gmail.com
$0
7/29/2026

Potential Use-After-Free in bssl-tls during Certificate Parsing due to dangling pool pointer

#503536060Reporter: rj...@google.com
$0
7/29/2026

Potential UAF and Double-Free in libwebm Segment::WriteFramesLessThan

#504660052Reporter: vm...@google.com
$0
7/29/2026

Potential Use-After-Free in js_injection::JsBinding due to lazy sweeping of Mojo receiver

#503889643Reporter: rj...@google.com
$0
7/29/2026
Showing 1341-1350 of 13102 bugs