Disclosed Chromium Security Bugs

Navigation API bypasses BlockingFocusWithoutUserActivation via hardcoded FocusTrigger::kUserGesture

#506392934Reporter: vm...@google.com
$0
8/13/2026

User gesture bypass via action.onUserSettingsChanged event

#505945112Reporter: vm...@google.com
$0
8/13/2026

Potential iOS Enterprise Data Controls (DLP) bypass in Reader Mode via missing delegate overrides

#504196549Reporter: vm...@google.com
$0
8/13/2026

Potential defense-in-depth regression: CRWWebUISchemeHandler drops security headers and sets wildcard CORS

#502503860Reporter: vm...@google.com
$0
8/13/2026

Missing browser-side visibility check for Pan/Tilt/Zoom in ImageCaptureImpl

#502493950Reporter: vm...@google.com
$0
8/13/2026

CSP bypass via mismatched policy counts in HTMLDocumentParser::AllowPreloading

#502358901Reporter: vm...@google.com
$0
8/13/2026

Potential iOS DataSharingTabHelper gesture gate bypass

#502090914Reporter: vm...@google.com
$0
8/13/2026

Potential seccomp bypass in Speech Recognition sandbox due to BPF DSL ternary logic error

#502023400Reporter: vm...@google.com
$0
8/13/2026

Potential UI spoofing and forced actions via X-Chrome-Manage-Accounts header on iOS

#501892820Reporter: vm...@google.com
$0
8/13/2026

Potential CCT EngagementSignals privacy guard bypass allows cross-origin text fragment oracle

#501859865Reporter: vm...@google.com
$0
8/13/2026
Showing 291-300 of 12354 bugs