Disclosed Chromium Security Bugs
←Back to DashboardV8 sandbox bypass: arbitrary bytecode execution with replaced bytecode array in lazy deoptimization throw
$20,000
4/18/2026
UAF Vulnerability in TrustedSpace Due To Turboshaft's Optimization of TrustedPointers in WebAssembly
$10,000
4/18/2026
CHECK failure: IsJSReceiver(*object) in json-stringifier.cc
$0
4/18/2026
CHECK failure: scope_info.scope_type() != ScopeType::SCRIPT_SCOPE in maglev-graph-builder.cc
$0
4/18/2026
WebGLOnWebGPU: draw allowed with invalid vertex / index buffer state
$8,000
4/17/2026
libGLES_mali UAF via WebGPU shaders at llvm::BasicBlock::getTerminator
$25,000
4/17/2026
Intersection Observer v2 API fails to correctly determine target's visibility for dynamically changed z-indexes, enabling clickjacking against Google One Tap
$5,000
4/17/2026
V8 Sandbox Bypass: Memory corruption during StringToBigInt conversion
$0
4/17/2026
Vulnerability: CVE-2025-66570: cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*) affecting GitOnBorg::chromium::crashpad::crashpad
$0
4/17/2026
cctest/test-api/Threading8 starts flaking
$0
4/17/2026