Disclosed Chromium Security Bugs

libyaml:libyaml_dumper_fuzzer: Use-of-uninitialized-value in yaml_document_delete

#42488030•Reporter: mo...@clusterfuzz-external.iam.gserviceaccount.com
$0
9/26/2024

wabt:wasm_objdump_fuzzer: Index-out-of-bounds in wabt::BinaryReaderObjdumpBase::GetSectionStart

#42528652•Reporter: mo...@clusterfuzz-external.iam.gserviceaccount.com
$0
9/26/2024

sigstore-java:CertificatesFuzzer: Security exception in org.bouncycastle.asn1.IndefiniteLengthInputStream.read

#42536579•Reporter: mo...@clusterfuzz-external.iam.gserviceaccount.com
$0
9/26/2024

AddressSanitizer: heap-use-after-free on ScreenCaptureKitDeviceMac::ResetStreamTo

#346898524•Reporter: li...@gmail.com
$6,000
9/26/2024

CHECK failure: (location_) != nullptr in maybe-handles.h

#347804248•Reporter: 24...@project.gserviceaccount.com
$0
9/26/2024

Segfault in v8 in Builtins_JSConstructStubGeneric

#347724915•Reporter: s0...@gmail.com
$7,000
9/26/2024

tint_wgsl_fuzzer: Incorrect-function-pointer-type in tint::hlsl::validate::ValidateUsingDXC

#348087176•Reporter: 24...@project.gserviceaccount.com
$0
9/26/2024

v8::Value string with unmatched UTF8 surrogate pair causes crash when converted to base::Value

#339141099•Reporter: go...@gmail.com
$3,000
9/25/2024

Extensions can run JS on any priveledged origin by using chrome.devtools.inspectedWindow.reload and crashing the page

#341136300•Reporter: ad...@gmail.com
$0
9/25/2024

GPU process crash via WebGPU shader - UAF in combineInstructionsOverFunction at InstructionCombining.cpp:3008

#342545100•Reporter: wg...@gmail.com
$10,000
9/25/2024
Showing 5491-5500 of 13102 bugs