Disclosed Chromium Security Bugs
←Back to DashboardPotential Use-After-Free of web::DownloadTask in iOS DownloadManagerCoordinator
$0
7/29/2026
Missing return after ShutdownForBadMessage in SimpleDevToolsProtocolClient leads to past-end OOB read in the browser process
$3,000
7/29/2026
Potential Use-after-free in HWNDMessageHandler::OnDpiChanged via nested message loops
$0
7/29/2026
Potential Cross-thread UAF in PipewireCaptureStream due to member destruction order
$0
7/29/2026
Renderer UAF in RTCEncodedVideoStreamTransformerDelegate via cross-thread WeakPtr usage
$0
7/29/2026
Potential UAF in RecentActivityCoordinator due to raw pointer capture bypassing BRP
$0
7/29/2026
Potential UAF via race condition in RTCVideoEncoder::Impl::SetSimulcastToSvcConverter
$0
7/29/2026
Potential cross-origin input redirection via unvalidated FrameSinkId in Viz hit-test
$0
7/29/2026
Potential TEE memory corruption via renderer-forged secure_handle in V4L2 video decoding
$0
7/29/2026
GPU Process UAF Write via Service ID Collision in VAO-Orphaned Buffers
$0
7/29/2026