Disclosed Chromium Security Bugs

Cross-origin EXIF orientation leak in NinePieceImagePainter

#502239897Reporter: vm...@google.com
$0
7/22/2026

Bypass of cross-origin EXIF-orientation clamp via CSS cross-fade()

#502231588Reporter: vm...@google.com
$0
7/22/2026

macOS .crwebloc file handler bypasses startup URL scheme allowlist

#502069297Reporter: vm...@google.com
$0
7/22/2026

CSP nonce hijacking via missing '

#500099106Reporter: vm...@google.com
$0
7/22/2026

Payment Method Manifest Default Applications Resolved Against Original Pre-Redirect URL

#497610654Reporter: vm...@google.com
$0
7/22/2026

Tab hovercard doesn't show the origin correctly

#448421954Reporter: sa...@gmail.com
$0
7/22/2026

Potential OOB Heap Write / RCE via Integer Overflow in CalculationValueHandleMap

#502322843Reporter: vm...@google.com
$0
7/22/2026

Potential privilege escalation in Linux CRD via uncleared supplementary groups

#502322596Reporter: vm...@google.com
$0
7/22/2026

Potential Renderer UAF via integer truncation and sentinel key collision in WTF::HashMap

#501676175Reporter: vm...@google.com
$0
7/22/2026

Potential Use-After-Free via data race in ChromeSpeechRecognitionClient

#501546443Reporter: vm...@google.com
$0
7/22/2026
Showing 451-460 of 11919 bugs