Disclosed Chromium Security Bugs

Prefill consent bypass via input keystroke in Perfetto UI Extension Servers

#517576726Reporter: vm...@google.com
$0
9/5/2026

flyway:LocationFuzzer: Security exception in com.code_intelligence.jazzer.sanitizers.RegexInjection.hookInternal

#537432125Reporter: 87...@developer.gserviceaccount.com
$0
9/4/2026

fast-dds:fuzz_proxy_cdr: Crash in eprosima::fastdds::dds::QosPoliciesSerializer

#532839120Reporter: 87...@developer.gserviceaccount.com
$0
9/4/2026

CHECK failure: length == previously_materialized_objects->ulength().value() in translated-state

#516833326Reporter: 24...@project.gserviceaccount.com
$0
9/4/2026

DCHECK failure in !pending_splice_.has_value() in maglev-reducer.h

#517243137Reporter: 24...@project.gserviceaccount.com
$0
9/4/2026

Stale static router state and zeroed COEP on controller change bypasses CORP check

#516827905Reporter: vm...@google.com
$0
9/4/2026

Use-After-Free in PostMessageSupport::PostJavaScriptMessage via synchronous getter

#516910450Reporter: vm...@google.com
$0
9/4/2026

Potential Use-After-Free and Wild Write in Graphite DrawBufferManager on Allocation Failure

#516981393Reporter: vm...@google.com
$0
9/4/2026

use-after-poison in ViewTransitionSupplement::OnTransitionCaptured

#517168239Reporter: tr...@gmail.com
$500
9/4/2026

Potential UAF in X11Window::OnWindowMapped after synchronous deletion during Maximize

#517050585Reporter: vm...@google.com
$0
9/4/2026
Showing 401-410 of 13102 bugs