Disclosed Chromium Security Bugs

libreoffice:sftfuzzer: Crash in vcl::ConvertCFFfontToType1

#513301090Reporter: 87...@developer.gserviceaccount.com
$0
7/8/2026

wolfssl:cryptofuzz-sp-math-all: Heap-buffer-overflow in sp_tohex

#520938073Reporter: 87...@developer.gserviceaccount.com
$0
7/8/2026

Use-after-free in Wasm: missing memory cache reload after WasmFX switch in Turboshaft

#497667917Reporter: th...@gmail.com
$0
7/8/2026

SpeechSynthesis audio can appear to originate from another domain after fast redirect (UI/Audio Spoofing – may trick users / tricky victim)

#489624550Reporter: ec...@gmail.com
$1,000
7/8/2026

OOB Read in ANGLE Metal Backend During Block-Compressed PBO Texture Upload Crashes GPU Process on Mac

#489579953Reporter: je...@gmail.com
$3,000
7/8/2026

FrameState: polymorphic Wasm accessor lazy deopt type confusion lead to in-sandbox corruption

#497404188Reporter: pj...@gmail.com
$10,000
7/8/2026

GPU memory information leak via premature SetInitialized in BlitTextureToBuffer

#497594413Reporter: vm...@google.com
$0
7/8/2026

ChromeDriver Argument Sanitization Bypass — Positional Argument Injection

#494464734Reporter: ia...@gmail.com
$500
7/8/2026

Potential RCE in Browser Process via out-of-bounds read in MediaSessionImpl

#497412658Reporter: rj...@google.com
$0
7/8/2026

Integer overflow in ANGLE D3D11 TextureStorage11::setData() leads to heap buffer overflow via WebGL2

#491760376Reporter: yu...@gmail.com
$5,000
7/8/2026
Showing 1921-1930 of 13102 bugs