Disclosed Chromium Security Bugs

v8_wasm_async_fuzzer: DCHECK failure in pc_offset() <= first_const_pool_32_use_ + kMaxDistToIntPool in assembler-arm.h

#40056529Reporter: cl...@chromium.org
$0
10/22/2021

Null-dereference READ in ubsan_GetStackTrace

#40056230Reporter: cl...@chromium.org
$0
10/21/2021

virgl_fuzzer: Use-of-uninitialized-value in vrend_destroy_shader_object

#40056412Reporter: cl...@chromium.org
$0
10/21/2021

tint_robustness_fuzzer.exe: Illegal-instruction in tint::fuzzers::FatalError

#40056522Reporter: cl...@chromium.org
$0
10/21/2021

Security DCHECK failure: as_image_observer_count_ > 0u in layout_object.cc

#40056477Reporter: cl...@chromium.org
$0
10/20/2021

Bad-cast to blink::LayoutObject from invalid vptr in blink::LayoutInline::SplitFlow

#40056530Reporter: cl...@chromium.org
$0
10/20/2021

Crash in blink::LayoutObject::SlowLastChild

#40056537Reporter: cl...@chromium.org
$0
10/20/2021

Heap-use-after-free in blink::Text::RecalcTextStyle

#40056538Reporter: cl...@chromium.org
$0
10/20/2021

Heap-use-after-free in blink::HasRenderedNonAnonymousDescendantsWithHeight

#40056539Reporter: cl...@chromium.org
$0
10/20/2021

tint_msl_transform_fuzzer: Heap-buffer-overflow in tint::writer::msl::GeneratorImpl::EmitTypeConstructor

#40056487Reporter: cl...@chromium.org
$0
10/19/2021
Showing 6111-6120 of 10939 bugs