Disclosed Chromium Security Bugs
←Back to DashboardV8 Sandbox Bypass: WasmCPT handle UAF by import dispatch table growth
$20,000
1/1/2026
Heap-use-after-free in ui::AcceleratorManager::Process
$0
1/1/2026
Heap-use-after-free in ui::AcceleratorManager::Process
$0
1/1/2026
Crash in v8::internal::compiler::ObjectData::IsBigInt
$0
1/1/2026
Crash in v8::internal::Map::instance_type
$0
1/1/2026
Crash in v8::internal::compiler::ObjectData::IsContext
$0
1/1/2026
Crash in v8::internal::compiler::JSNativeContextSpecialization::InferRootMap
$0
1/1/2026
Crash in v8::internal::compiler::HeapObjectRef::map
$0
1/1/2026
Crash in v8::internal::compiler::ObjectData::IsJSFunction
$0
1/1/2026
DCHECK failure in v8_flags.assert_hole_checked_by_value implies !SafeIsAnyHole(obj) in heap-object
$0
1/1/2026