Chromium Security Bugs

DCHECK failure in arg_repr == ValueRepresentation::kTagged in maglev-graph-builder.cc

#396192870Reporter: 24...@project.gserviceaccount.com
$0
5/27/2025

V8 Sandbox Bypass: Arbitrary code execution via OSR DeoptimizationData confusion

#395659804Reporter: se...@gmail.com
$20,000
5/27/2025

V8 Sandbox Bypass: AAW (wildcopy) due to %TypedArray%.prototype.set bounds check integer overflow

#391169061Reporter: se...@gmail.com
$20,000
5/27/2025

DCHECK failure in (isolate) != nullptr in isolate-inl.h

#393666930Reporter: 24...@project.gserviceaccount.com
$0
5/27/2025

Security: Chrome extension able to grant itself content setting permissions due to faulty pattern matching

#40086360Reporter: pu...@gmail.com
$1,000
5/24/2025

DCHECK failure in IsNativeContext(*this) in contexts-inl.h

#396460426Reporter: 24...@project.gserviceaccount.com
$0
5/24/2025

custom tab doesnt show main domain in samsung s24 ultra

#395544225Reporter: mr...@gmail.com
$3,000
5/23/2025

Bad-cast to v8::internal::(anonymous namespace)::PatternMap from invalid vptr in v8::internal::CreateData

#395732879Reporter: 24...@project.gserviceaccount.com
$0
5/22/2025

Bad-cast to icu_74::MeasureUnit from invalid vptr in v8::internal::CreateUnitMap

#395935914Reporter: 24...@project.gserviceaccount.com
$0
5/22/2025

V8 sandbox violation in v8::base::GenerateCountedDigits

#395029283Reporter: v8...@gmail.com
$5,000
5/22/2025
Showing 141-150 of 8153 bugs