Disclosed Chromium Security Bugs

Security: JBIG2_Context.cpp arithmetic looks prone to overflow.

#40058256Reporter: ts...@chromium.org
$0
4/20/2022

Security: heap-buffer-overflow in webui tabstrip

#40058358Reporter: ab...@microsoft.com
$0
4/20/2022

Security: Heap UAF in media_gpu!media::VideoProcessorProxy::VideoProcessorBlt

#40056669Reporter: ha...@gmail.com
$7,000
4/19/2022

Security: UAF in DateTimeChooserAndroid::ReplaceDateTime

#40058088Reporter: jt...@gmail.com
$25,000
4/19/2022

Security: UAF in BookmarkDragHelper::OnBookmarkIconLoaded

#40058319Reporter: jt...@gmail.com
$10,000
4/19/2022

Crash in cppgc::internal::MemberBase::MemberBase

#40058432Reporter: cl...@chromium.org
$0
4/19/2022

Crash in blink::LayoutObject::RemoveChild

#40058460Reporter: cl...@chromium.org
$0
4/19/2022

Security: Inappropriate implementation in PushMessaging

#40057994Reporter: jt...@gmail.com
$10,000
4/18/2022

Security: use-after-poison in blink::InspectorAccessibilityAgent::RefreshFrontendNodes

#40058326Reporter: ha...@gmail.com
$500
4/18/2022

AddressSanitizer: use-after-poison cc\layers\texture_layer.cc:169 in cc::TextureLayer::Update

#40058360Reporter: m....@gmail.com
$5,000
4/18/2022
Showing 5811-5820 of 10918 bugs