Disclosed Chromium Security Bugs

DCHECK failure in !value->properties().is_conversion() in maglev-interpreter-frame-state.h

#455339682Reporter: 24...@project.gserviceaccount.com
$0
2/3/2026

ffmpeg:ffmpeg_AV_CODEC_ID_VVC_fuzzer: Use-of-uninitialized-value in set_qp_c

#472635021Reporter: 87...@developer.gserviceaccount.com
$0
2/2/2026

DCHECK failure in NodeTypeIs(GetType(string), NodeType::kString) in maglev-graph-builder.cc

#455174878Reporter: 24...@project.gserviceaccount.com
$0
2/2/2026

Crash in Builtins_JumpIfToBooleanTrueHandler

#455069756Reporter: 24...@project.gserviceaccount.com
$0
2/2/2026

DCHECK failure in left != right in macro-assembler-arm.cc

#454841548Reporter: 24...@project.gserviceaccount.com
$0
2/1/2026

libvpx:vpx_enc_fuzzer_vp8: Use-of-uninitialized-value in vp8_diamond_search_sadx4

#479896934Reporter: 87...@developer.gserviceaccount.com
$0
1/31/2026

gpsd:FuzzDrivers: Use-of-uninitialized-value in aivdm_analyze

#479564939Reporter: 87...@developer.gserviceaccount.com
$0
1/31/2026

libraw:libraw_fuzzer: Index-out-of-bounds in LibRaw::ahd_interpolate_r_and_b_in_rgb_and_convert_to_cielab

#476973671Reporter: 87...@developer.gserviceaccount.com
$0
1/31/2026

cmake:cmELFFuzzer: Container-overflow in cmELFInternalImpl::GetNumberOfSections

#479251884Reporter: 87...@developer.gserviceaccount.com
$0
1/31/2026

Incorrect Optimization of ArrayConstructor by Maglev Leads to Creation of Malformed JSArray Objects

#454485895Reporter: hu...@gmail.com
$50,000
1/31/2026
Showing 191-200 of 9745 bugs