Disclosed Chromium Security Bugs

Bad-cast to blink::LayoutBlock from blink::LayoutImage in blink::LayoutBlock& blink::To

#40058712Reporter: cl...@chromium.org
$0
5/20/2022

Security: [0-day] Use-After-Free in UpdateAnimationTiming

#40058745Reporter: cl...@google.com
$0
5/20/2022

uaf in BrowserSwitchHandler::OnLaunchFinished

#40058583Reporter: wx...@gmail.com
$2,000
5/19/2022

renderer_proto_tree_fuzzer: Use-of-uninitialized-value in blink::NGLayoutResult::NGLayoutResult

#40058735Reporter: cl...@chromium.org
$0
5/19/2022

file_system_manager_mojolpm_fuzzer: Heap-use-after-free in storage::ObfuscatedFileUtil::GetDirectoryForStorageKey

#40058539Reporter: cl...@chromium.org
$0
5/18/2022

Crash in memfd:swiftshader_jit

#40058644Reporter: cl...@chromium.org
$0
5/18/2022

Cross-site information leak - CSP Violation reports contain blockedURI's hostname

#40057810Reporter: pr...@gmail.com
$2,000
5/16/2022

tint_wgsl_reader_spv_writer_fuzzer: Illegal-instruction in tint::fuzzers::CommonFuzzer::Run

#40058529Reporter: cl...@chromium.org
$0
5/15/2022

dawn_wire_server_and_frontend_fuzzer: Heap-use-after-free in tint::diag::Formatter::format

#40058649Reporter: cl...@chromium.org
$0
5/15/2022

Security DCHECK failure: IsA(from) in casting.h

#40058675Reporter: cl...@chromium.org
$0
5/14/2022
Showing 5741-5750 of 10918 bugs