Chromium Security Bugs

DCHECK failure in IsJSFunction(*callable) implies !Cast(*callable)->shared()->is_scrip

#403364367Reporter: 24...@project.gserviceaccount.com
$0
6/25/2025

intent:// can bypass fido:/ URI bock (see: 370482421)

#401823929Reporter: Si...@rawet.se
$2,000
6/25/2025

The maglev-pretenure-store-values feature leads to bypass of write barrier check

#400584607Reporter: hu...@gmail.com
$10,000
6/25/2025

DCHECK failure in ((static_cast(tagged_value) & ::i::kSmiTagMask) == ::i::kSmiTag) in

#403641209Reporter: 24...@project.gserviceaccount.com
$0
6/24/2025

UAF in net::HttpStreamPool::Group::ProcessPendingRequest

#399995424Reporter: 0x...@gmail.com
$10,000
6/22/2025

Type Confusion Vulnerability in Maglev When Handling TypedArray Length Loading

#402646504Reporter: hu...@gmail.com
$6,000
6/21/2025

Heap-use-after-free in chromium_jpeg_read_scanlines

#401846968Reporter: at...@gmail.com
$9,000
6/20/2025

Update libxslt to v1.1.43

#402714442Reporter: am...@chromium.org
$0
6/20/2025

Heap-use-after-free in blink::ImageDecodingStore::InsertDecoder

#402542600Reporter: 24...@project.gserviceaccount.com
$0
6/20/2025

Stack-use-after-scope in blink::Shape::CreateLayoutBoxShape

#402863515Reporter: 24...@project.gserviceaccount.com
$0
6/20/2025
Showing 81-90 of 8152 bugs
1...8910...816