Disclosed Chromium Security Bugs

V8 Sandbox Bypass: WasmCPT handle UAF by import dispatch table corruption (multiple variants of b/446113730)

#452605803Reporter: se...@gmail.com
$20,000
2/6/2026

webnn_graph_mojolpm_fuzzer: Negative-size-param in void tflite::reference_ops::BroadcastTo<8>

#450406597Reporter: 24...@project.gserviceaccount.com
$0
2/6/2026

kimageformats:kimgio_jxr_fuzzer: Use-of-uninitialized-value in ReadContainer

#461325309Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

libheif:file_fuzzer: Negative-size-param in HeifPixelImage::fill_RGB_16bit

#480200609Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

kimageformats:kimgio_xcf_fuzzer: Use-of-uninitialized-value in comp_func_SourceOver_avx2

#462673332Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

ffmpeg:ffmpeg_AV_CODEC_ID_QDM2_fuzzer: Heap-use-after-free in qdm2_get_vlc

#476179569Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

libheif:file_fuzzer: Heap-buffer-overflow in Op_RGB_to_YCbCr::convert_colorspace

#479872242Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

libssh2:ssh2_client_fuzzer: Heap-buffer-overflow in session_startup

#474401005Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

libheif:file_fuzzer: Heap-buffer-overflow in HeifPixelImage::scale_nearest_neighbor

#479872448Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

kimageformats:kimgio_heif_fuzzer: Use-of-uninitialized-value in put_weighted_pred_8_fallback

#480258830Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026
Showing 171-180 of 9745 bugs