Disclosed Chromium Security Bugs
←Back to DashboardPotential above-lock-screen UI spoofing via AnnotationsOverlayViewImpl navigation bypass
$0
9/12/2026
Potential UAF write in ConsentDialogCoordinator::Show due to macOS nested run loop
$0
9/12/2026
Use-After-Free read of an external string in the WebAssembly `js-string` `substring` builtin (`WasmStringViewWtf16Slice`)
$0
9/12/2026
Potential GPU OOB read/write via WebNN resample2d precision divergence in ONNX/DML
$0
9/12/2026
Potential Use-After-Free in ShowSettingsOverriddenDialog due to macOS nested run loop
$0
9/11/2026
ExtensionInstallSources bypass via forged DownloadURLParams
$0
9/11/2026
V8 Sandbox Bypass: WasmGetOwnProperty's no-write/no-throw effects allow a forged accessor to create mixed call_indirect dispatch and a native tiering-budget OOB write
$2,500
9/11/2026
Potential UXSS guard bypass via presentation-time TOCTOU in iOS Bookmarks
$0
9/11/2026
Off-Space CPPT Entry Update Produces a Native Write Outside the V8 Sandbox
$0
9/11/2026
V8 Sandbox Bypass: EPT compaction null-handle bailout leaves a pooled exact-tag Managed entry pointing to freed native memory
$2,500
9/11/2026