Disclosed Chromium Security Bugs

apache-poi:POIFileHandlerFuzzer: Security exception in org.apache.poi.hemf.record.emf.HemfMisc$EmfExtCreatePen.init

#520101146Reporter: 87...@developer.gserviceaccount.com
$0
6/5/2026

Use-after-free in CreateNewWindow via SINGLETON_TAB disposition leads to sandbox escape

#487338366Reporter: je...@gmail.com
$90,000
6/5/2026

DevTools cookie write/delete APIs allow extensions to modify cookies for enterprise policy-blocked sites despite runtime_blocked_hosts restrictions

#479673903Reporter: po...@gmail.com
$0
6/5/2026

Signed integer overflow in UniqueTimestampCounter::Add leads to heap buffer underflow via negative array index

#486498791Reporter: je...@gmail.com
$3,000
6/5/2026

chrome://image allows arbitrary images to be navigated to as a trusted chrome page

#40059921Reporter: rd...@chromium.org
$0
6/5/2026

Use-after-free in MIDIPortMap iterator due to untracked raw pointers surviving Oilpan compaction leads to renderer crash

#485935314Reporter: je...@gmail.com
$2,000
6/5/2026

Sandbox escape: renderer -> arbitrary file read via modified PageState

#487383169Reporter: rj...@google.com
$0
6/5/2026

Select Option can be opened on top of Popups with Different Origins and can be used to Spoof important Security Prompts

#365089001Reporter: fa...@gmail.com
$0
6/5/2026

Detached ArrayBuffer UAF after AB view tracking was enabled

#487336007Reporter: er...@gmail.com
$8,000
6/5/2026

V8 Sandbox Bypass: V8 JSPI StackMemory use-after-free via EPT entry not invalidated on retirement

#485784597Reporter: ad...@gmail.com
$0
6/5/2026
Showing 2381-2390 of 13102 bugs