Disclosed Chromium Security Bugs
←Back to DashboardAudio player's download functionality allows bypassing the "allow-downloads" flag of sandboxed iframes
$1,000
5/29/2026
Unblocked :// Characters on `data:text`origin value lead to File Source Origin Spoofing
$0
5/29/2026
Mini bar not rendering when omnibox is hidden on Pixel 8 and 9
$1,000
5/29/2026
Authorization Bypass in Target.exposeDevToolsProtocol via Missing Early Return
$4,000
5/29/2026
Unviersal CSP Bypass/XSS & Privileged chrome:// page XSS via Browser History Sidebar navigation
$1,000
5/29/2026
Heap OOB read in SpeechRecognizerImpl::AddAudioFromRenderer
$36,000
5/29/2026
Heap Buffer Overflow in TFLite + XNNPack via WebNN
$33,000
5/29/2026
Heap-buffer-overflow in CSSUnparsedValue::FindVariableName
$11,000
5/29/2026
Security: Heap-use-after-free in SecureChannelImpl::OnDecryptedResponse
$11,000
5/29/2026
libyal:libfsxfs_file_entry_fuzzer: Heap-buffer-overflow in libfsxfs_directory_table_read_data
$0
5/28/2026