Disclosed Chromium Security Bugs

Heap-buffer-overflow read in libavformat `mov_seek_stream` / `can_seek_to_key_sample` via a crafted HEVC MP4 and an HTMLMediaElement seek

#507090179Reporter: qw...@gmail.com
$3,000
8/13/2026

Forged audio_forwarder in SpeechRecognition IPC bypasses per-origin microphone permission on Android

#508092634Reporter: je...@gmail.com
$8,000
8/13/2026

Potential UXSS / Privileged Navigation via Missing URL Scheme Validation in Lens SDK Integration

#508293203Reporter: li...@chromium.org
$0
8/13/2026

Browser Process Type Confusion in DataSharingSDKDelegateDesktop

#501669642Reporter: vm...@google.com
$0
8/13/2026

Potential OOB write in browser via Starboard media subsample integer signedness flip

#499025645Reporter: vm...@google.com
$0
8/13/2026

heap-buffer-overflow in TabDragController::AttachToNewContext

#505371980Reporter: xp...@gmail.com
$2,000
8/13/2026

V8 Sandbox Escape: CppHeapPointerTable evacuation entry causes out-of-sandbox CppGC mark-bit write

#506570358Reporter: sm...@gmail.com
$5,000
8/13/2026

AddressSanitizer heap-buffer-overflow in skcms CLUT from a PNG iCCP chunk on the default Rust ICC path

#504103236Reporter: oj...@gmail.com
$2,000
8/13/2026

Security: heap-use-after-free in extensions::ExtensionInstallTimePermissionProvider::GetRuleIterator

#507356235Reporter: zh...@gmail.com
$6,000
8/13/2026

Thread-unsafe base::WeakPtr dereference leads to potential UAF in CompoundImageBacking

#497136403Reporter: rj...@google.com
$0
8/13/2026
Showing 961-970 of 13102 bugs