Disclosed Chromium Security Bugs

Vulnerability: multiple vulnerabilities affecting GitOnBorg::chromium::catapult

#404229414Reporter: au...@google.com
$0
6/26/2025

chrome_tint_wgsl_fuzzer_ChromiumTintWgslTest_CanConvertWgslToIRWithoutCrashing_fuzzer: Crash in re2::Balinese_range16

#403308736Reporter: 24...@project.gserviceaccount.com
$0
6/26/2025

DCHECK failure in IsJSFunction(*callable) implies !Cast(*callable)->shared()->is_scrip

#403364367Reporter: 24...@project.gserviceaccount.com
$0
6/25/2025

intent:// can bypass fido:/ URI bock (see: 370482421)

#401823929Reporter: Si...@rawet.se
$2,000
6/25/2025

The maglev-pretenure-store-values feature leads to bypass of write barrier check

#400584607Reporter: hu...@gmail.com
$10,000
6/25/2025

DCHECK failure in ((static_cast(tagged_value) & ::i::kSmiTagMask) == ::i::kSmiTag) in

#403641209Reporter: 24...@project.gserviceaccount.com
$0
6/24/2025

harfbuzz:hb-draw-fuzzer: Use-of-uninitialized-value in CFF::cff2_cs_opset_t

#405454658Reporter: 87...@developer.gserviceaccount.com
$0
6/23/2025

unicorn:fuzz_emu_x86_32: Crash in pcmpxstrx

#406054619Reporter: 87...@developer.gserviceaccount.com
$0
6/23/2025

UAF in net::HttpStreamPool::Group::ProcessPendingRequest

#399995424Reporter: 0x...@gmail.com
$10,000
6/22/2025

Type Confusion Vulnerability in Maglev When Handling TypedArray Length Loading

#402646504Reporter: hu...@gmail.com
$6,000
6/21/2025
Showing 481-490 of 8577 bugs