Disclosed Chromium Security Bugs

Wasm type confusion due to custom descriptors spec unsoundness on `ref.func` exact typing

#446113731Reporter: se...@gmail.com
$55,000
12/31/2025

Wasm type confusion due to spec unsoundness in `cast_desc` operations

#446113732Reporter: se...@gmail.com
$55,000
12/31/2025

Crash in v8::internal::ObjectStatsCollectorImpl::CollectStatistics

#446778618Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

Crash with empty stacktrace

#446239322Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

Crash in v8::internal::ObjectStatsCollectorImpl::RecordVirtualObjectsForConstantPoolOrEmb

#446261252Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

Crash in v8::internal::Map::instance_size_in_words

#446057766Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

CHECK failure: ValueRepresentationIs(input->properties().value_representation(), NodeT::kInputT

#446096116Reporter: 24...@project.gserviceaccount.com
$0
12/31/2025

checkstyle:CheckstyleFuzzer: Security exception in com.puppycrawl.tools.checkstyle.grammar.java.JavaLanguageParser.statement

#472346779Reporter: 87...@developer.gserviceaccount.com
$0
12/30/2025

mruby:mruby_fuzzer: Segv on unknown address in scope_new

#471816957Reporter: 87...@developer.gserviceaccount.com
$0
12/30/2025

mruby:mruby_fuzzer: Use-of-uninitialized-value in codegen_masgn

#472140765Reporter: 87...@developer.gserviceaccount.com
$0
12/30/2025
Showing 441-450 of 9745 bugs