Disclosed Chromium Security Bugs

tint_all_transforms_fuzzer: Use-of-uninitialized-value in tint::fuzzers::Reader::string

#40056610•Reporter: cl...@chromium.org
$0
11/2/2021

Redirects should be handled by CSP form-action in a spec-compliant way

#40085903•Reporter: lu...@chromium.org
$0
10/30/2021

Referrer Policy bypass with javascript URL

#40090848•Reporter: s....@gmail.com
$1,000
10/30/2021

Security: Possible to escape sandbox via devtools_page (alternative method)

#40052752•Reporter: de...@gmail.com
$5,000
10/30/2021

dawn_wire_server_and_d3d12_backend_fuzzer.exe: Heap-use-after-free in dawn_wire::server::Server::InjectDevice::::__invoke

#40056327•Reporter: cl...@chromium.org
$0
10/29/2021

dawn_wire_server_and_vulkan_backend_fuzzer: Heap-use-after-free in dawn_wire::server::Server::InjectDevice

#40056335•Reporter: cl...@chromium.org
$0
10/29/2021

Security: HeapOverflow in RecentlyUsedFoldersComboModel

#40056467•Reporter: le...@gmail.com
$20,000
10/29/2021

Heap-use-after-free in blink::NGOutOfFlowLayoutPart::SaveStaticPositionOnPaintLayer

#40056471•Reporter: cl...@chromium.org
$0
10/29/2021

dawn_wire_server_and_frontend_fuzzer: Use-of-uninitialized-value in void dawn_wire::ChunkedCommandSerializer::SerializeCommandImpl

#40056489•Reporter: cl...@chromium.org
$0
10/29/2021

Security: Chrome: UAF in BindFileUtilitiesHost

#40056549•Reporter: so...@gmail.com
$20,000
10/29/2021
Showing 8241-8250 of 13102 bugs