Disclosed Chromium Security Bugs

Security: HTTP 302 can navigate to non-web-accessible chrome-extension:// URIs

#40083753Reporter: ql...@gmail.com
$0
9/23/2016

Use-after-poison in blink::CrossThreadPersistentRegion::prepareForThreadStateTermination

#40084544Reporter: cl...@chromium.org
$0
9/20/2016

Security: Heap-use-after-free in autofill components

#40084206Reporter: ro...@robwu.nl
$1,000
8/31/2016

Heap-use-after-free in blink::LayoutObject::containingBlock

#40084223Reporter: at...@gmail.com
$3,500
8/31/2016

Security: Devtools allows running privileged scripts via XSS on chrome-devtools-frontend.appspot.com

#40084203Reporter: gr...@gmail.com
$3,500
8/23/2016

Heap-use-after-free in v8::Isolate::VisitHandlesWithClassIds

#40084289Reporter: th...@gmail.com
$3,500
8/18/2016

Heap-use-after-free in blink::DeferredTaskHandler::handleDirtyAudioNodeOutputs

#40084274Reporter: at...@gmail.com
$3,500
8/17/2016

Security: Heap-use-after-free in AutofillAgent::FillFieldWithValue

#40084205Reporter: ro...@robwu.nl
$1,000
8/15/2016

Bad-cast to v8::internal::AstNode from invalid vptr;wasm-js.cc:138:7

#40084144Reporter: cl...@chromium.org
$0
8/9/2016

Heap-use-after-free in blink::LayoutBoxModelObject::invalidateStickyConstraints

#40083992Reporter: at...@gmail.com
$3,500
7/12/2016
Showing 9191-9200 of 13102 bugs