Disclosed Chromium Security Bugs

Sandbox Escape in GPU Process via Type Confusion in ANGLE RewriteStructSamplers

#500030250Reporter: vm...@google.com
$0
9/1/2026

Renderer-supplied embedding_token can potentially hijack browser-process AXActionHandlerRegistry

#503333798Reporter: vm...@google.com
$0
9/1/2026

[SPIR-V 1.4] libGLES_mali memory safety violation in DenseMapBase::FindAndConstruct

#498659375Reporter: an...@gmail.com
$32,000
9/1/2026

Potential bypass of Secure Payment Confirmation (SPC) trusted transaction review UI

#514018717Reporter: vm...@google.com
$0
9/1/2026

tarantool:uri_parse_test: Heap-use-after-free in cdata_setptr

#551018371Reporter: 87...@developer.gserviceaccount.com
$0
8/31/2026

curl:curl_fuzzer_gopher: Heap-buffer-overflow in gid_cb

#530086148Reporter: 87...@developer.gserviceaccount.com
$0
8/31/2026

DCHECK failure in !IsInitializing(store_mode) implies !value->is_conversion() in maglev-graph-buil

#515992451Reporter: 24...@project.gserviceaccount.com
$0
8/31/2026

vlc:vlc-demux-dec-libfuzzer-gme: Heap-buffer-overflow in Ay_Emu::start_track_

#519260589Reporter: 87...@developer.gserviceaccount.com
$0
8/30/2026

Potential OOB write in GPU process via GLES2 ReadPixels validator desync

#513165325Reporter: vm...@google.com
$0
8/30/2026

State desync and draw validation bypass in ANGLE GL backend via Transform Feedback

#513919827Reporter: vm...@google.com
$0
8/30/2026
Showing 541-550 of 13102 bugs