Disclosed Chromium Security Bugs

tint_msl_transform_fuzzer: Heap-buffer-overflow in tint::writer::msl::GeneratorImpl::EmitTypeConstructor

#40056993Reporter: cl...@chromium.org
$0
12/3/2021

tint_renamer_fuzzer: Stack-use-after-return in tint::sem::Pointer::Pointer

#40057047Reporter: cl...@chromium.org
$0
12/3/2021

Security: Possible to download files from sandboxed frames

#40052718Reporter: de...@gmail.com
$3,000
12/2/2021

Security: Web GPU - Out of bound object manupilation in WebGPUImplementation::OnGpuControlReturnData()

#40056885Reporter: lo...@gmail.com
$7,500
12/2/2021

tint_regex_spv_writer_fuzzer.exe: Illegal-instruction in tint::fuzzers::FatalError

#40056926Reporter: cl...@chromium.org
$0
12/1/2021

TALOS-2021-1352: Google Chrome Blink setBaseAndExtent use after free vulnerability

#40056812Reporter: ma...@gmail.com
$7,500
11/30/2021

heap-use-after-free : WebUIAllowlist::GetRuleIterator

#40056834Reporter: cr...@system.gserviceaccount.com
$0
11/30/2021

M94 Merge Request for crbug.com/dawn/837

#40056937Reporter: en...@chromium.org
$0
11/30/2021

media_h265_decoder_fuzzer: Heap-buffer-overflow in media::H265Decoder::CalcRefPicPocs

#40056955Reporter: cl...@chromium.org
$0
11/30/2021

Security: CVE-2021-3560 local privilege escalation through polkit

#40056973Reporter: ae...@google.com
$0
11/29/2021
Showing 6031-6040 of 10933 bugs