Disclosed Chromium Security Bugs

skia_image_filter_proto_fuzzer: Null-dereference READ in skia_image_filter_proto_converter::Converter::Visit

#41485129Reporter: cl...@chromium.org
$0
3/27/2024

Security: Chrome OS : PowerVR GPU Driver Controllable OOB Writes because of Integer overflows in function DevmemIntChangeSparse

#40070894Reporter: pi...@gmail.com
$0
3/27/2024

Security: Debug check failed: HasFeedbackMetadata(kAcquireLoad)

#40948107Reporter: wh...@gmail.com
$1,000
3/26/2024

Security: Use After Free in sqlite

#41484271Reporter: gc...@gmail.com
$1,000
3/26/2024

Security: [V8] [turboshaft] Yet another minus zero case missing when typing divisions.

#40943982Reporter: in...@gmail.com
$11,000
3/26/2024

DCHECK failure in label->predecessor_count_ > 1 in maglev-graph-builder.cc

#41484597Reporter: cl...@chromium.org
$0
3/24/2024

sql_recovery_fuzzer: Null-dereference READ in sql::recover::LeafPayloadReader::Initialize

#41483762Reporter: cl...@chromium.org
$0
3/24/2024

Security: Title : Debug check failed: Asm().current_block()->IsMerge() && inputs.size() == Asm().current_block()->Predecessors().size(). in v8, leading to SEGV

#41483711Reporter: je...@gmail.com
$8,000
3/23/2024

Security: container-overflow in ChromeOSSystemProfileProvider::WriteLinkedAndroidPhoneProto(metrics::SystemProfileProto*)

#40940871Reporter: 0x...@gmail.com
$0
3/23/2024

Cherry-pick the fix for AV1 video encoder bugs b/314858909, b/310455204 to the Chrome M121 branch

#41483975Reporter: wt...@google.com
$0
3/22/2024
Showing 3551-3560 of 10591 bugs