Disclosed Chromium Security Bugs

Security: Dangling FixedArray pointers in Torque lead to memory corruption

#40068417Reporter: gl...@google.com
$0
11/9/2023

Debug check failed: IsKind(TypeBase::kWasm) in WasmLoadElimination::HalfState::KillField

#40068537Reporter: az...@google.com
$0
11/9/2023

Security: Race Condition UAF in i915_perf_add_config_ioctl

#40062573Reporter: lm...@gmail.com
$16,000
11/8/2023

Security: Race Condition UAF in mtk_jpeg_job_timeout_work

#40063406Reporter: lm...@gmail.com
$5,000
11/7/2023

Security: Users cannot escape the full screen mode in this offline .html file

#40065810Reporter: du...@gmail.com
$3,000
11/7/2023

Security: chrome.devtools.inspectedWindow.eval can bypass enterprise-policy blocked hosts using subframes

#40068096Reporter: ha...@gmail.com
$500
11/7/2023

net_quic_stream_factory_fuzzer: Heap-use-after-free in net::QuicChromiumClientStream::Handle::ReadBody

#40067502Reporter: cl...@chromium.org
$0
11/6/2023

Security: v8 error Received signal 11 SEGV_MAPERR 000000000dd0

#40068179Reporter: be...@gmail.com
$0
11/6/2023

Security: LoadPropertyFromGlobalDictionary checks the wrong hole

#40068402Reporter: sr...@google.com
$0
11/6/2023

Security: [GPU/Angle] heap-buffer-overflow WRITE of size 496 [@rx::PackPixels]

#40066451Reporter: Di...@microsoft.com
$0
11/4/2023
Showing 4081-4090 of 10725 bugs