Disclosed Chromium Security Bugs
←Back to DashboardV8 Sandbox Bypass: OOB Write using %TypedArray%.prototype.set due to element type/size TOCTOU
$7,000
4/24/2026
V8 Sandbox Bypass: AAW due to JSArrayBuffer extension handle double fetch
$20,000
4/24/2026
Potential parameter count mismatch via `SharedFunctionInfoRef::GetBytecodeArray()`
$0
4/24/2026
lua:string_len_test: Crash in arena_for_chunk
$0
4/23/2026
libvips:vips_fuzzer: Heap-buffer-overflow in vips_stdif_generate
$0
4/23/2026
c-blosc2:decompress_frame_fuzzer: Use-of-uninitialized-value in get_coffset
$0
4/23/2026
skcms:iccprofile_transform: Heap-buffer-overflow in skcms_private::baseline::clut
$0
4/23/2026
freetype2:truetype-render-i35: Heap-buffer-overflow in TT_RunIns
$0
4/23/2026
libvips:vips_fuzzer: Heap-buffer-overflow in vips_bandjoin_const_buffer
$0
4/23/2026
thrift-java:RoundtripCompactFuzzer: Security exception in org.apache.thrift.protocol.TProtocolUtil.skip
$0
4/23/2026