Disclosed Chromium Security Bugs

CHECK failure: ref.IsSmi() || ref.IsHeapNumber() || ref.HoleType() == HoleType::kNone

#501783138Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026

DCHECK failure in !IsTheHole(argument) in elements.cc

#501693323Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026

DCHECK failure in !elements->is_the_hole(isolate_, i) in json-stringifier.cc

#501785647Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026

DCHECK failure in obj.is_null() || IsSmi(*obj) || !IsTheHole(*obj) in api-inl.h

#501549285Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026

CHECK failure: has_exception()

#502714072Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026

DCHECK failure in Holder v8::internal::TrustedCast(Holder, SourceLocation) [To = v8::int

#502797494Reporter: sa...@google.com
$0
7/23/2026

DCHECK failure in !IsTheHole(heap_object) in api.cc

#501946344Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026

DCHECK failure in IsHole(raw_exception) implies raw_exception == ReadOnlyRoots{this}.termination_e

#502657880Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026

DCHECK failure in IsPrimitiveMap(*this) || instance_type() == WASM_NULL_TYPE in map-inl.h

#501559731Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026

DCHECK failure in !IsTheHole(*value, isolate_) in lookup.cc

#501559197Reporter: 24...@project.gserviceaccount.com
$0
7/23/2026
Showing 1551-1560 of 13102 bugs