Disclosed Chromium Security Bugs

V8 Sandbox Bypass: Fast API overload metadata corruption causes compiler-emitted mixed native call type confusion

#492077213Reporter: gu...@gmail.com
$5,000
7/9/2026

Potential GPU OOB Access via Integer Overflow in Dawn D3D12 Texture Allocation Workaround

#497565944Reporter: vm...@google.com
$0
7/9/2026

Potential Local File Disclosure via Drag-and-Drop Frame Confusion

#496393078Reporter: vm...@google.com
$0
7/9/2026

Potential Double-Free in BitmapInSharedMemory Deserialization via SkBitmap::installPixels

#497846428Reporter: rj...@google.com
$0
7/9/2026

Extensions without file URL access can use the `Page.navigate` CDP command to open `view-source:file:` URLs

#491766258Reporter: al...@gmail.com
$2,000
7/9/2026

Bypass of Secure Payment Confirmation dialog via Page.setSPCTransactionMode

#496426191Reporter: vm...@google.com
$0
7/9/2026

Potential Local Privilege Escalation in CECA net worker via retained supplementary groups on macOS

#497828892Reporter: vm...@google.com
$0
7/9/2026

Protocol handler hijacking via Page.setRPHRegistrationMode

#496373088Reporter: vm...@google.com
$0
7/9/2026

Potential web_accessible_resources bypass via missing TargetHandler::Session delegation

#495853686Reporter: vi...@google.com
$0
7/9/2026

Potential Renderer-to-GPU sandbox escape via OOB access in D3D12 AV1 encode driver

#497821764Reporter: vm...@google.com
$0
7/9/2026
Showing 1891-1900 of 13102 bugs