Disclosed Chromium Security Bugs

Extensions can hijack Gemini in the browser webview process to perform PE attacks by abusing DNR permissions, allowing stealing prompts, PII leakage, unrestricted access to camera-microphone and more

#463155954Reporter: we...@gmail.com
$7,000
3/4/2026

Bottom Minibar Fails to Display URL – Potential Phishing via Spoof Bar

#461532432Reporter: ch...@gmail.com
$2,000
3/3/2026

Security: Heap-use-after-free in LoginStateChecker::OnExecutionResponseCallback

#460599518Reporter: me...@gmail.com
$3,000
2/28/2026

Cross thread stack corruption caused by RTCVideoDecoderAdapter::InitializeSync

#461214000Reporter: al...@gmail.com
$2,000
2/28/2026

Security: SEGV_ACCERR 000044332211 in V8

#460678755Reporter: je...@gmail.com
$8,000
2/25/2026

Extensions can run JS on any privileged origin by exploiting already-patched vulnerabilities under devtools:// scheme.

#439058242Reporter: le...@gmail.com
$4,000
2/24/2026

Bypass #443948855 - Allows Arbitrary Code Execution via "Copy as cURL (cmd)" in DevTools

#455899538Reporter: we...@gmail.com
$1,000
2/20/2026

DCHECK Fail when Maglev Generates Exception Handler Trampoline Instructions

#457351015Reporter: hu...@gmail.com
$10,000
2/17/2026

Windows download logic flaw: % triggers double extension sanitization bypass (.lnk .lnk, .scf .scf)

#444803530Reporter: br...@gmail.com
$3,000
2/11/2026

Security: opens a new window at the same time as the previous window in fullscreen mode, (the window enters fullscreen mode which is closed by another new window) leads to spoof

#40074800Reporter: sa...@gmail.com
$1,000
2/11/2026
Showing 1-10 of 1667 bugs