Disclosed Chromium Security Bugs

Potential cross-domain credential metadata leak to renderer via manual fallback hover preview

#518082781Reporter: vm...@google.com
$0
9/9/2026

Potential ActorLogin Prompt Bypass and Cross-Origin Password Exfiltration via Same-Site Iframe

#518945524Reporter: vm...@google.com
$0
9/9/2026

Sandbox Escape in Loong64 CallOrConstructVarargs via Sign-Extended Length

#516517853Reporter: aw...@chromium.org
$0
9/9/2026

Potential WebUSB blocklist bypass via concurrent ClaimInterface and SetConfiguration TOCTOU

#517936145Reporter: vm...@google.com
$0
9/9/2026

json-flattener:FlattenFuzzer: Security exception in com.github.wnameless.json.flattener.JsonFlattener.jsonVal2Obj

#539212294Reporter: 87...@developer.gserviceaccount.com
$0
9/8/2026

json-flattener:AdvancedFuzzer: Security exception in com.github.wnameless.json.base.JsonValueUtils.toMap

#530072443Reporter: 87...@developer.gserviceaccount.com
$0
9/8/2026

mongoose:fuzz: Heap-buffer-overflow in ppp_tx_frame

#546440470Reporter: 87...@developer.gserviceaccount.com
$0
9/8/2026

json-flattener:FlattenFuzzer: Security exception in com.github.wnameless.json.flattener.JsonFlattener.jsonVal2Obj

#553637751Reporter: 87...@developer.gserviceaccount.com
$0
9/8/2026

json-flattener:AdvancedFuzzer: Security exception in com.google.gson.internal.bind.TypeAdapters$28.write

#533951265Reporter: 87...@developer.gserviceaccount.com
$0
9/8/2026

hostap:eapol-key-auth: Crash in eapol-key-auth.c

#556787437Reporter: 87...@developer.gserviceaccount.com
$0
9/8/2026
Showing 291-300 of 13102 bugs