Disclosed Chromium Security Bugs

libheif:file_fuzzer: Negative-size-param in HeifPixelImage::fill_RGB_16bit

#480200609Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

kimageformats:kimgio_xcf_fuzzer: Use-of-uninitialized-value in comp_func_SourceOver_avx2

#462673332Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

ffmpeg:ffmpeg_AV_CODEC_ID_QDM2_fuzzer: Heap-use-after-free in qdm2_get_vlc

#476179569Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

libheif:file_fuzzer: Heap-buffer-overflow in Op_RGB_to_YCbCr::convert_colorspace

#479872242Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

libssh2:ssh2_client_fuzzer: Heap-buffer-overflow in session_startup

#474401005Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

libheif:file_fuzzer: Heap-buffer-overflow in HeifPixelImage::scale_nearest_neighbor

#479872448Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

kimageformats:kimgio_heif_fuzzer: Use-of-uninitialized-value in put_weighted_pred_8_fallback

#480258830Reporter: 87...@developer.gserviceaccount.com
$0
2/5/2026

clickjacking (enterjacking) download notification when a pip window closes

#392375329Reporter: sa...@gmail.com
$1,000
2/5/2026

gpsd:FuzzClient: Use-of-uninitialized-value in ntrip_parse_url

#479908873Reporter: 87...@developer.gserviceaccount.com
$0
2/4/2026

gpac:fuzz_probe_analyze: Heap-buffer-overflow in avi_parse_input_file

#480506470Reporter: 87...@developer.gserviceaccount.com
$0
2/4/2026
Showing 461-470 of 10084 bugs