Disclosed Chromium Security Bugs

Crash in v8::internal::compiler::JSNativeContextSpecialization::InferRootMap

#446730213•Reporter: 24...@project.gserviceaccount.com
$0
1/1/2026

Crash in v8::internal::compiler::HeapObjectRef::map

#446730212•Reporter: 24...@project.gserviceaccount.com
$0
1/1/2026

Crash in v8::internal::compiler::ObjectData::IsJSFunction

#446561512•Reporter: 24...@project.gserviceaccount.com
$0
1/1/2026

DCHECK failure in v8_flags.assert_hole_checked_by_value implies !SafeIsAnyHole(obj) in heap-object

#446190088•Reporter: 24...@project.gserviceaccount.com
$0
1/1/2026

Crash in v8::internal::Map::instance_type

#446205020•Reporter: 24...@project.gserviceaccount.com
$0
1/1/2026

checkstyle:CheckstyleFuzzer: Security exception in com.puppycrawl.tools.checkstyle.grammar.java.JavaLanguageParser.expr

#467964460•Reporter: 87...@developer.gserviceaccount.com
$0
12/31/2025

mruby:mruby_fuzzer: Use-of-uninitialized-value in scope_new

#472564069•Reporter: 87...@developer.gserviceaccount.com
$0
12/31/2025

checkstyle:CheckstyleFuzzer: Security exception in com.puppycrawl.tools.checkstyle.JavaAstVisitor.getInnerBopAst

#472247330•Reporter: 87...@developer.gserviceaccount.com
$0
12/31/2025

Wasm type confusion due to custom descriptors spec ambiguity in `ref.get_desc` exactness typing

#446124893•Reporter: se...@gmail.com
$55,000
12/31/2025

Wasm type confusion due to missing exactness check on JS-Wasm boundary

#446124892•Reporter: se...@gmail.com
$55,000
12/31/2025
Showing 3641-3650 of 13102 bugs