Disclosed Chromium Security Bugs
←Back to DashboardV8 Sandbox Bypass:TypedArray.prototype.set ElementsKind TOCTOU
$5,000
7/23/2026
V8: JIT Miscompilation via Incorrect Type Narrowing in TurboFan SpeculativeAdditiveSafeIntegerAdd
$3,000
7/23/2026
DCHECK-only validation of WebRTC APM output buffer size leads to heap buffer overflow from compromised renderer
$4,000
7/23/2026
Use-After-Free Write in PasswordGenerationAgent via synchronous re-entry
$0
7/23/2026
Potential cross-user VM access via --owner_id injection in openVmshellProcess
$0
7/23/2026
Potential Use-After-Free in WebrtcVideoRendererAdapter via mutable MediaStream tracks
$0
7/23/2026
Potential Type Confusion in AccessibilityNodeInfoDataWrapper leads to Arbitrary Free
$0
7/23/2026
Potential cross-thread UAF in CommandBufferHelperImpl via Windows GPU Video Encoders
$0
7/23/2026
Potential UAF in FedCM UI during synchronous view destruction
$0
7/23/2026
Arbitrary file write via path traversal in feedback_util::ZipString
$0
7/23/2026