Disclosed Chromium Security Bugs

Use-after-poison in blink::MessagePort::~MessagePort

#40067398Reporter: cl...@chromium.org
$0
10/21/2023

Security: stack OOB in xfrm_state_find

#40063364Reporter: v4...@theori.io
$1,000
10/20/2023

Security: Segment Fault in v8 wasm at address > page size

#40067181Reporter: je...@gmail.com
$1,000
10/20/2023

Security: shouldLimitTypeSizes check bypassable from a compromised renderer

#40067391Reporter: ti...@google.com
$0
10/20/2023

DCHECK failure in !shared_heap_worklist_.has_value() in marking-barrier.cc

#40067405Reporter: cl...@chromium.org
$0
10/20/2023

Security: Picture in picture can hide fullscreen notification

#40063918Reporter: sa...@gmail.com
$1,000
10/19/2023

CVE-2023-26966 and CVE-2023-2908 were fixed in libtiff and published but not propagated to Pdfium yet

#40067271Reporter: [Deleted User]
$0
10/19/2023

Security: Web Share dialog URL is incorrectly elided in Android (ineffective fix for issue 1329541)

#40061104Reporter: al...@alesandroortiz.com
$1,000
10/18/2023

CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsHeapObject()) in heap-

#40067249Reporter: cl...@chromium.org
$0
10/18/2023

v8_wasm_fuzzer: Crash in v8::internal::RootScavengeVisitor::VisitRootPointer

#40067288Reporter: cl...@chromium.org
$0
10/18/2023
Showing 4201-4210 of 10765 bugs