Disclosed Chromium Security Bugs

ffmpeg:ffmpeg_AV_CODEC_ID_AAC_LATM_fuzzer: Crash in ff_aac_usac_decode_frame

#393523547•Reporter: 87...@developer.gserviceaccount.com
$0
5/1/2025

Eliminate raw pointers to traceable disallow_new types in css/

#389707046•Reporter: om...@chromium.org
$0
5/1/2025

stack-use-after-scope in SetColorFromScheme(FPDF_COLORSCHEME_ const*, CPDF_RenderOptions*) fpdfsdk/cpdfsdk_helpers.cpp: 498:42

#390887851•Reporter: ss...@snu.ac.kr
$0
5/1/2025

DCHECK failure in current_block_->HasBackedge(graph_) in wasm-gc-typed-optimization-reducer.cc

#383814042•Reporter: 24...@project.gserviceaccount.com
$0
5/1/2025

Heap use-after-free in DirectSocket API

#390590778•Reporter: tk...@paloaltonetworks.com
$4,000
4/30/2025

libGLES_mali memory safety violation via WebGPU shaders at llvm::Value::setNameImpl

#379551588•Reporter: a7...@gmail.com
$35,000
4/30/2025

libical:libical_extended_fuzzer: Heap-use-after-free in icalreqstattype_as_string_r

#392948871•Reporter: 87...@developer.gserviceaccount.com
$0
4/29/2025

V8 Sandbox Bypass: UB in WebAssemblyMemoryGrow because AddressType is constructed from on-heap data

#390453039•Reporter: v8...@gmail.com
$5,000
4/29/2025

V8 Sandbox Bypass: UB in MessageHandler::GetMessage because of invalid MessageTemplate variant

#390568183•Reporter: v8...@gmail.com
$5,000
4/29/2025

rdkit:mol_data_stream_to_mol_fuzzer: Crash in RDKit::Dict::reset

#391962480•Reporter: 87...@developer.gserviceaccount.com
$0
4/28/2025
Showing 4851-4860 of 13102 bugs