Disclosed Chromium Security Bugs

Potential OOB Heap Read in CRD SYSTEM Daemon via Malicious ETW Events

#501900366Reporter: vm...@google.com
$0
7/25/2026

Potential Publisher Proof Bypass for Initial Installs of Webstore Extensions

#500551122Reporter: vm...@google.com
$0
7/25/2026

Use-After-Free in Android HaTS MessageWrapper via bypass of Java MessageDispatcher

#502072755Reporter: vm...@google.com
$0
7/25/2026

Bypass of attr()-security via discrete transitions on registered custom properties

#501801823Reporter: vm...@google.com
$0
7/25/2026

CRD Host Hijack via missing config key filtering in UpdateConfig (Linux/macOS)

#501709220Reporter: vm...@google.com
$0
7/25/2026

Potential Use-After-Free in OtpVerificationDialogViewAndroid during dismissal animation

#501561644Reporter: vm...@google.com
$0
7/25/2026

Potential IWA Key Rotation Bypass via Unconditional Acceptance of Compromised Previous Key

#500468338Reporter: vm...@google.com
$0
7/25/2026

Potential Heap OOB Write in GPU process via unvalidated VP9 VA-API spatial layers

#500293394Reporter: vm...@google.com
$0
7/25/2026

Potential Sandbox Escape via RemoteViews Inflation Filter Bypass in Custom Tabs

#497936421Reporter: vm...@google.com
$0
7/25/2026

Cross-origin URL interception via PWA wildcard scope extension logic flaw

#497538899Reporter: vm...@google.com
$0
7/25/2026
Showing 1441-1450 of 13102 bugs