Disclosed Chromium Security Bugs

CHECK failure: marking_state_->IsBlackOrGrey(heap_object)

#40057964Reporter: cl...@chromium.org
$0
3/4/2022

Segv on unknown address in tint::writer::msl::Options::operator=

#40057991Reporter: cl...@chromium.org
$0
3/4/2022

Security: heap-use-after-free in DevToolsWindow::ActivateWindow

#40058000Reporter: ab...@microsoft.com
$0
3/4/2022

Security: heap-use-after-free in DevToolsWindow::Show

#40058001Reporter: ab...@microsoft.com
$0
3/4/2022

Crash in blink::NGInlineItemsBuilderTemplate::AppendTex

#40058010Reporter: cl...@chromium.org
$0
3/4/2022

CHECK failure: (location_) != nullptr in maybe-handles.h

#40058022Reporter: cl...@chromium.org
$0
3/4/2022

The destruction timing issue between RenderFrameHostImpl and DedicatedWorkerHost/DedicatedWorkerHostFactoryImpl

#40054797Reporter: m....@gmail.com
$0
3/3/2022

Security: Pointer lock can be used to bypass mouse movement/keyboard input requirements for autofill

#40056870Reporter: al...@alesandroortiz.com
$3,000
3/3/2022

Security: Autofill prompt for a page can render over different origin, allows spoofing of autofill context origin

#40056880Reporter: al...@alesandroortiz.com
$5,000
3/3/2022

Security: Heap-use-after-free in ui::EventDispatcher::DispatchEventToEventHandlers()

#40057864Reporter: ch...@gmail.com
$1,000
3/3/2022
Showing 5911-5920 of 10930 bugs