Disclosed Chromium Security Bugs

Potential origin confusion in SubresourceFilter bubble allows persistent cross-origin ads allowlisting

#513832989Reporter: vm...@google.com
$0
8/26/2026

Potential TOCTOU in DevTools AI Assistance origin lock allows cross-origin data disclosure

#513727626Reporter: vm...@google.com
$0
8/26/2026

Potential WebUSB Protected Interface Policy Bypass on Linux-based Platforms

#513394321Reporter: vm...@google.com
$0
8/26/2026

Potential security prompt bypass via WeakPtr fail-open in ActorNavigationThrottle

#512937764Reporter: vm...@google.com
$0
8/26/2026

TargetHandlerAndroid::CreateTarget missing IsTrusted/MayReadLocalFiles check

#512249559Reporter: li...@gmail.com
$0
8/26/2026

Potential CSS Injection via unescaped identifiers in CSSCounterValue serialization

#514429130Reporter: rj...@google.com
$0
8/26/2026

Potential mXSS via unescaped @position-try rule name serialization

#514420555Reporter: rj...@google.com
$0
8/26/2026

Browser Process UAF in HeadlessDevToolsManagerDelegate::DisposeBrowserContext

#513822378Reporter: vm...@google.com
$0
8/26/2026

macOS Google Updater: Potential root LPE via Mojo heap-use-after-free write

#513371963Reporter: vm...@google.com
$0
8/26/2026

Potential Local Privilege Escalation in Chrome Updater via Mojo Ipcz handle relaying

#500108770Reporter: vm...@google.com
$0
8/26/2026
Showing 701-710 of 13102 bugs