Disclosed Chromium Security Bugs

Potential above-lock-screen UI spoofing via AnnotationsOverlayViewImpl navigation bypass

#525332327Reporter: vm...@google.com
$0
9/12/2026

Potential UAF write in ConsentDialogCoordinator::Show due to macOS nested run loop

#534862220Reporter: vm...@google.com
$0
9/12/2026

Use-After-Free read of an external string in the WebAssembly `js-string` `substring` builtin (`WasmStringViewWtf16Slice`)

#543901836Reporter: ja...@outlook.com
$0
9/12/2026

Potential GPU OOB read/write via WebNN resample2d precision divergence in ONNX/DML

#541732324Reporter: aw...@chromium.org
$0
9/12/2026

Potential Use-After-Free in ShowSettingsOverriddenDialog due to macOS nested run loop

#534863145Reporter: vm...@google.com
$0
9/11/2026

ExtensionInstallSources bypass via forged DownloadURLParams

#511772271Reporter: vm...@google.com
$0
9/11/2026

V8 Sandbox Bypass: WasmGetOwnProperty's no-write/no-throw effects allow a forged accessor to create mixed call_indirect dispatch and a native tiering-budget OOB write

#543557673Reporter: sm...@gmail.com
$2,500
9/11/2026

Potential UXSS guard bypass via presentation-time TOCTOU in iOS Bookmarks

#517581661Reporter: vm...@google.com
$0
9/11/2026

Off-Space CPPT Entry Update Produces a Native Write Outside the V8 Sandbox

#536234354Reporter: am...@openai.com
$0
9/11/2026

V8 Sandbox Bypass: EPT compaction null-handle bailout leaves a pooled exact-tag Managed entry pointing to freed native memory

#540656748Reporter: sm...@gmail.com
$2,500
9/11/2026
Showing 11-20 of 13102 bugs