Disclosed Chromium Security Bugs

Potential Safe Browsing bypass for nested archives in DMGs due to logic errors in DMGAnalyzer

#495840862Reporter: vm...@google.com
$0
8/13/2026

Potential Use-After-Free in UserScriptSet::UpdateUserScripts via shared memory mapping failure

#493225428Reporter: rj...@google.com
$0
8/13/2026

Fenced frame `_unfencedTop` navigation leaks `initiator_origin` to destination via `Sec-Fetch-Site`

#487564032Reporter: os...@gmail.com
$3,000
8/13/2026

VerifyInitiatorOrigin() skips HostsOrigin() process lock check for opaque origins in error documents and MHTML subframes

#487300831Reporter: os...@gmail.com
$2,000
8/13/2026

Previous page executes JS after navigation, allowing history.back() tab hijack

#480074849Reporter: mr...@gmail.com
$2,000
8/13/2026

Popup window tab doesn't show the origin correctly

#458442542Reporter: sa...@gmail.com
$1,000
8/13/2026

Site Isolation bypass via error page precursors and sandboxed srcdoc frames

#502348223Reporter: vm...@google.com
$0
8/13/2026

Parser differential in experimental Rust XML lexer via chunk boundaries

#502285273Reporter: vm...@google.com
$0
8/13/2026

Info leak of global UMA data via metricsPrivate.getHistogram in chrome-untrusted://

#502256049Reporter: vm...@google.com
$0
8/13/2026

Potential cross-origin info leak via uninitialized Skia stencil buffer

#501861921Reporter: vm...@google.com
$0
8/13/2026
Showing 321-330 of 12354 bugs