Disclosed Chromium Security Bugs

DCHECK failure in obj.is_null() || IsSmi(*obj) || !IsTheHole(*obj) in api-inl.h

#422099361Reporter: 24...@project.gserviceaccount.com
$0
9/14/2025

opencv:core_fuzzer: Heap-buffer-overflow in png_combine_row

#444754937Reporter: 87...@developer.gserviceaccount.com
$0
9/13/2025

DCHECK failure in IsHeapNumber(*number) implies Cast(number)->value_as_bits() != kUnde

#422811228Reporter: 24...@project.gserviceaccount.com
$0
9/13/2025

UAF in StackSampler

#421471016Reporter: ha...@gmail.com
$4,000
9/13/2025

CHECK failure: (value & uint64_t{ADDRESS}) != unexpected || (value & uint64_t{ADDRESS}) == uint

#416907157Reporter: 24...@project.gserviceaccount.com
$0
9/13/2025

envoy:evaluator_fuzz_test: Use-after-poison in std::__1::basic_string, std::__1::allocator

#435894354Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025

spirv-cross:parser_fuzzer: Crash in spirv_cross::SPIRBlock* spirv_cross::ObjectPool::allocat

#427814449Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025

vlc:vlc-demux-dec-libfuzzer-mp4: Heap-buffer-overflow in FragPrepareChunk

#437694938Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025

vlc:vlc-demux-dec-libfuzzer-h265: Heap-buffer-overflow in cc_storage_append

#437855564Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025

opencv:imdecode_fuzzer: Bad-cast to cv::PngDecoder from invalid vptr in cv::PngDecoder::readData

#426783958Reporter: 87...@developer.gserviceaccount.com
$0
9/12/2025
Showing 71-80 of 8555 bugs
1...789...856