Disclosed Chromium Security Bugs

Potential UAF in V4L2VideoEncodeAccelerator bypassing MiraclePtr via cross-thread WeakPtr destruction

#500139116Reporter: vm...@google.com
$0
7/23/2026

Potential Race Condition in VmaAllocator with VulkanFromANGLE and DrDc

#500083376Reporter: vm...@google.com
$0
7/23/2026

Potential OOB read in AshMojomVideoConsumer::Frame::CreateSkBitmap via unvalidated content_rect

#491921410Reporter: rj...@google.com
$0
7/23/2026

DriveFS ConnectToExtension allows sandbox escape via unvalidated target extension ID

#501893497Reporter: vm...@google.com
$0
7/23/2026

mupdf:pdf_fuzzer: Crash in fz_unicode_from_glyph_name

#529965999Reporter: 87...@developer.gserviceaccount.com
$0
7/22/2026

libssh:ssh_client_config_fuzzer: Heap-buffer-overflow in ssh_config_parse_line_internal

#523820519Reporter: 87...@developer.gserviceaccount.com
$0
7/22/2026

Use-after-free of std::list iterator in FormFiller::UndoAutofill via duplicate FieldGlobalIds

#494740162Reporter: je...@gmail.com
$3,000
7/22/2026

Heap OOB read in ANGLE via `CubeMapArray` texture upload due to `endByte` underestimation in `ValidImageDataSize`

#494823889Reporter: se...@gmail.com
$3,000
7/22/2026

Security: double-free in blink::WebRtcVideoFrameAdapter::SharedResources::ScaleAndMapFrameAsync

#494823867Reporter: zh...@gmail.com
$11,000
7/22/2026

Type confusion in BuildCheckSmi constant folding in V8/Maglev

#500880819Reporter: qq...@calif.io
$55,000
7/22/2026
Showing 431-440 of 11919 bugs