Disclosed Chromium Security Bugs

Wasm type confusion due to wrong reachability analysis in `WasmGCTypeAnalyzer::ProcessBranchOnTarget()` with custom descriptor casts

#446122633•Reporter: se...@gmail.com
$55,000
12/31/2025

Wasm type confusion due to custom descriptors spec unsoundness on `ref.func` exact typing

#446113731•Reporter: se...@gmail.com
$55,000
12/31/2025

Wasm type confusion due to spec unsoundness in `cast_desc` operations

#446113732•Reporter: se...@gmail.com
$55,000
12/31/2025

Crash in v8::internal::ObjectStatsCollectorImpl::CollectStatistics

#446778618•Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

Crash with empty stacktrace

#446239322•Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

Crash in v8::internal::ObjectStatsCollectorImpl::RecordVirtualObjectsForConstantPoolOrEmb

#446261252•Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

Crash in v8::internal::Map::instance_size_in_words

#446057766•Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

CHECK failure: ValueRepresentationIs(input->properties().value_representation(), NodeT::kInputT

#446096116•Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

checkstyle:CheckstyleFuzzer: Security exception in com.puppycrawl.tools.checkstyle.grammar.java.JavaLanguageParser.statement

#472346779•Reporter: 87...@developer.gserviceaccount.com
$0
12/30/2025

mruby:mruby_fuzzer: Segv on unknown address in scope_new

#471816957•Reporter: 87...@developer.gserviceaccount.com
$0
12/30/2025
Showing 3651-3660 of 13102 bugs