Disclosed Chromium Security Bugs

Security: heap-use-after-free third_party\blink\renderer\core\workers\worker_thread.cc:905 in blink::WorkerThread::PauseOrFreezeOnWorkerThread

#40061275Reporter: m....@gmail.com
$7,000
1/23/2023

iOS Chrome Modal Dialog Spoof resulting to URL Spoof

#40061297Reporter: pr...@gmail.com
$5,000
1/23/2023

sleuthkit:sleuthkit_fls_ntfs_fuzzer: Heap-buffer-overflow in tsk_UTF16toUTF8

#42520336Reporter: mo...@clusterfuzz-external.iam.gserviceaccount.com
$0
1/22/2023

Security: heap-use-after-free on aura::WindowOcclusionTracker::MaybeObserveAnimatedWindow

#40061159Reporter: rh...@gmail.com
$1,000
1/21/2023

DCHECK failure in JSFunction::cast(entry.map(isolate).GetConstructor()) == native_context.array_fu

#40061348Reporter: cl...@chromium.org
$0
1/21/2023

Security: Heap-use-after-free in SpeechRecognitionRecognizerImpl::ChangeLanguage

#40061294Reporter: tt...@gmail.com
$10,000
1/19/2023

Security: WebGPU: Out of bounds write in OnBufferMapAsyncCallback

#40061304Reporter: ti...@chromium.org
$0
1/19/2023

v8_regexp_parser_fuzzer: DCHECK failure in index <= known_captures in regexp-parser.cc

#40061332Reporter: cl...@chromium.org
$0
1/19/2023

chrome.debugger API bypasses the runtime_blocked_hosts cookie protection

#40060283Reporter: nd...@protonmail.com
$3,000
1/18/2023

Security: .url files can be saved via getFileHandle and redirect showSaveFilePicker to arbitrary file

#40060617Reporter: ha...@gmail.com
$1,000
1/18/2023
Showing 5061-5070 of 10831 bugs