Disclosed Chromium Security Bugs

Potential Use-After-Free in ash-chrome via dangling DragDropDelegate in exo::DataDevice

#501817936Reporter: vm...@google.com
$0
7/24/2026

Potential FD Use-After-Close in ProcessProxy::Write via unsequenced ThreadPool task

#501616308Reporter: vm...@google.com
$0
7/24/2026

Double Free in Browser Process via GuestView Attach Race

#502055648Reporter: vm...@google.com
$0
7/24/2026

V8 Sandbox Bypass: double-free in HandleScope::Extend via concurrent JS stack printing from MainMarkingVisitor and ConcurrentMarkingVisitor

#501136000Reporter: gu...@gmail.com
$5,000
7/24/2026

Potential OOB access in GPU process via rank-0 Slice in WebNN ORT backend

#499051067Reporter: vm...@google.com
$0
7/24/2026

Potential stale FD double-close in Dawn ImportedTextureBase

#501762953Reporter: vm...@google.com
$0
7/24/2026

Potential GPU RCE via missing MSRTSS flag on imported textures in Dawn

#501764112Reporter: vm...@google.com
$0
7/24/2026

Potential UAF in Dawn via thread-safety race during device loss and Tint ICE

#498731543Reporter: vm...@google.com
$0
7/24/2026

Potential GPU memory leak in Dawn due to LazyClear ignoring RenderPassRenderArea

#501780768Reporter: vm...@google.com
$0
7/24/2026

Cross-Thread UAF in WebGPU logging callback with WebGPUMultithreadDawnWireOnWorkers

#501475310Reporter: vm...@google.com
$0
7/24/2026
Showing 1471-1480 of 13102 bugs