Disclosed Chromium Security Bugs

tint_inspector_fuzzer.exe: Illegal-instruction in tint::fuzzers::FatalError

#40056568•Reporter: cl...@chromium.org
$0
11/4/2021

dawn_wire_server_and_frontend_fuzzer: Bad-cast to dawn_wire::server::Server from invalid vptr in dawn_wire::server::Server::InjectDevice

#40056691•Reporter: cl...@chromium.org
$0
11/4/2021

CHECK failure: !map.is_dictionary_map() implies map.is_stable()

#40056713•Reporter: cl...@chromium.org
$0
11/4/2021

dawn_wire_server_and_frontend_fuzzer: Bad-cast to dawn_wire::server::Serverdawn_wire::server::Server::InjectDevice in dawn_native::LoggingCallbackTask::HandleShutDown

#40056722•Reporter: cl...@chromium.org
$0
11/4/2021

Security: heap-buffer-overflow in TabStripModel::IsTabBlocked

#40056132•Reporter: yu...@gmail.com
$0
11/2/2021

Heap-use-after-free in ash::DesksBarView::FinalizeDragDesk

#40056290•Reporter: cl...@chromium.org
$0
11/2/2021

use after free content::FontAccessManagerImpl::DidChooseLocalFonts

#40056362•Reporter: wx...@gmail.com
$20,000
11/2/2021

Security: SkAbort_FileLine Assert Failed

#40056376•Reporter: ha...@gmail.com
$0
11/2/2021

CHECK failure: addr + size <= chunk_->area_end()

#40056482•Reporter: cl...@chromium.org
$0
11/2/2021

tint_binding_remapper_fuzzer: Heap-buffer-overflow in tint::fuzzers::ExtractBindingRemapperInputs

#40056608•Reporter: cl...@chromium.org
$0
11/2/2021
Showing 8231-8240 of 13102 bugs