Disclosed Chromium Security Bugs

V8 Sandbox Bypass:TypedArray.prototype.set ElementsKind TOCTOU

#499717570Reporter: gr...@gmail.com
$5,000
7/23/2026

V8: JIT Miscompilation via Incorrect Type Narrowing in TurboFan SpeculativeAdditiveSafeIntegerAdd

#499659070Reporter: ca...@gmail.com
$3,000
7/23/2026

DCHECK-only validation of WebRTC APM output buffer size leads to heap buffer overflow from compromised renderer

#493957495Reporter: je...@gmail.com
$4,000
7/23/2026

Use-After-Free Write in PasswordGenerationAgent via synchronous re-entry

#498815068Reporter: vm...@google.com
$0
7/23/2026

Potential cross-user VM access via --owner_id injection in openVmshellProcess

#501370041Reporter: vm...@google.com
$0
7/23/2026

Potential Use-After-Free in WebrtcVideoRendererAdapter via mutable MediaStream tracks

#501722605Reporter: vm...@google.com
$0
7/23/2026

Potential Type Confusion in AccessibilityNodeInfoDataWrapper leads to Arbitrary Free

#501572586Reporter: vm...@google.com
$0
7/23/2026

Potential cross-thread UAF in CommandBufferHelperImpl via Windows GPU Video Encoders

#501388286Reporter: vm...@google.com
$0
7/23/2026

Potential UAF in FedCM UI during synchronous view destruction

#502726329Reporter: rj...@google.com
$0
7/23/2026

Arbitrary file write via path traversal in feedback_util::ZipString

#502248774Reporter: vm...@google.com
$0
7/23/2026
Showing 1511-1520 of 13102 bugs