Disclosed Chromium Security Bugs

DCHECK failure in kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)) in tagged-impl.h

#379843860Reporter: 24...@project.gserviceaccount.com
$0
3/11/2025

Check if WasmImportData::call_origin allows sandbox escapes

#369748454Reporter: jk...@chromium.org
$0
3/11/2025

MemorySanitizer: SEGV v8/src/heap/remembered-set-inl.h:46:38 in heap::base::SlotCallbackResult v8::internal::UpdateTypedSlotHelper::UpdateTypedSlot(v8::internal::WritableJitAllocation&, v8::internal::Heap*, v8::internal::SlotType, unsigned long, v8::internal::Scavenger::ScavengePage(v8::internal::MutablePageMetadata*)::$_2)

#380474992Reporter: al...@goodmanemail.com
$0
3/11/2025

Memory corruption in TransitiveTypeFeedbackProcessor with --wasm-deopt and multi-instance modules

#381281318Reporter: ml...@chromium.org
$0
3/11/2025

openbabel:fuzz_convert: Object-size in OpenBabel::GaussianOutputFormat::ReadMolecule

#383170469Reporter: 87...@developer.gserviceaccount.com
$0
3/10/2025

openbabel:fuzz_convert: Global-buffer-overflow in OpenBabel::generate_sequence

#382922246Reporter: 87...@developer.gserviceaccount.com
$0
3/10/2025

bluez:fuzz_xml: Null-dereference READ in ubsan_GetStackTrace

#382927066Reporter: 87...@developer.gserviceaccount.com
$0
3/10/2025

shaderc:shaderc_fdp_fuzzer: Crash in glslang::TInfoSinkBase::location

#382922237Reporter: 87...@developer.gserviceaccount.com
$0
3/10/2025

maven-model:Xpp3ReaderFuzzer: Security exception in org.apache.maven.internal.xml.XmlNodeStaxBuilder.build

#382816019Reporter: 87...@developer.gserviceaccount.com
$0
3/10/2025

shaderc:shaderc_fdp_fuzzer: Heap-buffer-overflow in glslang::HlslGrammar::acceptDeclaration

#382721848Reporter: 87...@developer.gserviceaccount.com
$0
3/10/2025
Showing 2461-2470 of 10541 bugs