Disclosed Chromium Security Bugs

gpsd:FuzzDrivers: Segv on unknown address in gpsd_vlog

#490142464•Reporter: 87...@developer.gserviceaccount.com
$0
3/12/2026

assimp:assimp_fuzzer_glb: Heap-buffer-overflow in aiColor4t* GetVertexColorsForType

#486378385•Reporter: 87...@developer.gserviceaccount.com
$0
3/12/2026

gpsd:FuzzDrivers: Crash in nmeaid_to_prn

#486727024•Reporter: 87...@developer.gserviceaccount.com
$0
3/12/2026

DCHECK failure in Holder v8::internal::TrustedCast(Holder, SourceLocation) [To = v8::int

#465554073•Reporter: 24...@project.gserviceaccount.com
$0
3/12/2026

DCHECK failure in Holder v8::internal::TrustedCast(Holder, SourceLocation) [To = v8::int

#465459516•Reporter: 24...@project.gserviceaccount.com
$0
3/12/2026

V8 correctness failure in sources: b6

#464965404•Reporter: 24...@project.gserviceaccount.com
$0
3/12/2026

DCHECK failure in Holder v8::internal::TrustedCast(Holder, SourceLocation) [To = v8::int

#465474033•Reporter: 24...@project.gserviceaccount.com
$0
3/12/2026

DCHECK failure in Holder v8::internal::TrustedCast(Holder, SourceLocation) [To = v8::int

#465488602•Reporter: 24...@project.gserviceaccount.com
$0
3/12/2026

V8: OOB memmove in FixedArray::MoveElements triggered via Array.shift leads to negative-size copy

#464459404•Reporter: am...@gmail.com
$5,000
3/12/2026

V8 Sandbox Bypass: AAW/PC control via dispatch entry UAF during InstantiateAsmJs by hijacking start

#462217236•Reporter: kr...@gmail.com
$20,000
3/12/2026
Showing 3131-3140 of 13102 bugs