Disclosed Chromium Security Bugs
←Back to DashboardPotential Use-After-Free in WebrtcVideoRendererAdapter via mutable MediaStream tracks
$0
7/23/2026
Potential Type Confusion in AccessibilityNodeInfoDataWrapper leads to Arbitrary Free
$0
7/23/2026
Potential cross-thread UAF in CommandBufferHelperImpl via Windows GPU Video Encoders
$0
7/23/2026
Potential UAF in FedCM UI during synchronous view destruction
$0
7/23/2026
Arbitrary file write via path traversal in feedback_util::ZipString
$0
7/23/2026
Browser-process heap UAF read in TerminalSource due to data race
$0
7/23/2026
TOCTOU in MHTMLGenerationManager allows DOM exfiltration via BFCache race
$0
7/23/2026
Use-after-free in DevToolsRendererChannel::ForceDetachWorkerSessions via duplicate ChildTargetCreated for dedicated workers
$26,000
7/23/2026
Heap UAF in Blink OffscreenCanvas
$7,000
7/23/2026
V8 Sandbox Bypass: Gin FunctionTemplateInfo EPT Type Confusion via Shared ExternalPointerTag
$5,000
7/23/2026