Disclosed Chromium Security Bugs

Potential Use-After-Free in WorkspaceWindowResizer via MultiWindowResizeController

#503774711Reporter: vm...@google.com
$0
8/13/2026

WebGL indexed-draw validation truncation on ANGLE Metal allows out-of-bounds vertex fetches

#505056913Reporter: mu...@winfunc.com
$2,000
8/13/2026

Integer wrap in ANGLE IndexRange allows WebGL OOB vertex fetch

#504175501Reporter: ra...@gmail.com
$2,000
8/13/2026

Potential Heap OOB write via size desynchronization in ANGLE D3D self-copy

#506377574Reporter: vm...@google.com
$0
8/13/2026

Potential arbitrary screen pixel leak via TOCTOU in CroppingWindowCapturerWin

#504557432Reporter: vm...@google.com
$0
8/13/2026

Potential integer overflow in ANGLE IndexRange bypasses software robust-buffer-access validation

#506375217Reporter: vm...@google.com
$0
8/13/2026

webnn_graph_impl_fuzzer_WebNNGraphImplFuzzer_GPU_SubgraphDQGemmQ_fuzzer: Incorrect-function-pointer-type in pack_weights_and_biases

#501948628Reporter: 24...@project.gserviceaccount.com
$0
8/13/2026

V8 Sandbox Bypass:LOCAL+frame OOB write in `SetLocalVariableValue`

#503553602Reporter: gr...@gmail.com
$5,000
8/13/2026

Potential stack buffer overflow in TFLite MEAN operation via arbitrary axis_count

#500048233Reporter: rj...@google.com
$0
8/13/2026

BoringSSL X.509 URI name constraint bypass — excluded domains evaded via userinfo (@), fragment (#), query (?), percent-encoding (%40), and port (:) in URI SAN

#502006234Reporter: su...@kentech.ac.kr
$0
8/13/2026
Showing 361-370 of 12354 bugs