Disclosed Chromium Security Bugs

Potential Cross-thread Use-After-Free in GnomeDisplayConfigDBusClient

#513727494Reporter: vm...@google.com
$0
8/28/2026

Potential local file read via scheme-less URI bypass in SelectFileDialog.java

#511735715Reporter: vm...@google.com
$0
8/28/2026

Concurrent V8 Isolate Access in OfflineAudioDestinationHandler

#513750691Reporter: vm...@google.com
$0
8/28/2026

TOCTOU in HLS BYTERANGE check enables cross-origin data oracle

#513395977Reporter: vm...@google.com
$0
8/28/2026

Potential Browser-process Heap UAF in HelpBubbleEventRelay::OnEvent

#513135965Reporter: vm...@google.com
$0
8/28/2026

Incorrect fix for CVE-2026-7905

#514531776Reporter: tu...@gmail.com
$0
8/28/2026

Potential Race Condition and UAF in MidiManagerAndroid leading to JNI Type Confusion

#514742327Reporter: vm...@google.com
$0
8/28/2026

Potential macOS Sandbox Escape via TOCTOU in GpuHost::CreateWebNNWeightsFile

#513244402Reporter: vm...@google.com
$0
8/28/2026

32-bit signed overflow in IndexedBufferBindingHost allows OOB GPU access

#500132379Reporter: vm...@google.com
$0
8/28/2026

V8 Sandbox Bypass: Turboshaft: three exhaustive switches over sandbox-corruptible enums missing UNREACHABLE() - incomplete fix for aee2fe73cc9 (sandbox UB audit)

#514860625Reporter: uv...@gmail.com
$500
8/28/2026
Showing 601-610 of 13102 bugs