Disclosed Chromium Security Bugs

Security: Chrome incorrectly interprets newlines in HTTP headers in HTTP/3, allowing for some header splitting possibilities

#40056840Reporter: on...@gmail.com
$1,000
1/10/2022

Google Chrome WebRTC RTPSenderVideoFrameTransformerDelegate memory corruption vulnerability (TALOS-2021-1372)

#40057198Reporter: vu...@sourcefire.com
$7,500
1/10/2022

CHECK failure: all.IsLive(use) && (use->opcode() == IrOpcode::kIfTrue || use->opcode() == IrOpc

#40057485Reporter: cl...@chromium.org
$0
1/10/2022

tint_ast_spv_writer_fuzzer: Illegal-instruction in tint::fuzzers::FatalError

#40057343Reporter: cl...@chromium.org
$0
1/7/2022

Security: UAF in IdentityDialogController::ShowIdProviderWindow

#40057362Reporter: jt...@gmail.com
$25,000
1/5/2022

Security: heap-use-after-free in PPAPIDownloadRequest::AllowlistCheckComplete

#40057113Reporter: me...@gmail.com
$20,000
1/1/2022

tint_vertex_pulling_fuzzer: Use-of-uninitialized-value in tint::fuzzers::DataBuilder::string

#40057381Reporter: cl...@chromium.org
$0
1/1/2022

Referrer Spoof using and

#40056681Reporter: pr...@gmail.com
$500
12/30/2021

SEGV in vk::Image::clear()

#40057228Reporter: at...@gmail.com
$5,000
12/30/2021

tint_binding_remapper_fuzzer: Heap-buffer-overflow in tint::fuzzers::RandomGenerator::CalculateSeed

#40057361Reporter: cl...@chromium.org
$0
12/30/2021
Showing 5981-5990 of 10930 bugs