Disclosed Chromium Security Bugs
←Back to DashboardsetHTML() fails open on invalid SanitizerConfig, inserting unsanitized HTML with active scripts into the live DOM
$2,000
7/10/2026
ANGLE Metal Shadow Buffer Stale Size causes GPU OOB WRITE
$18,000
7/10/2026
Maglev: unsound node replacement when inlining can lead to exploitable write barrier omission
$55,000
7/10/2026
UAF in Metal LibraryCache
$16,000
7/10/2026
Integer overflow in TFLite StridedSlice output dimension computation leads to heap buffer overflow in the GPU process
$43,000
7/9/2026
OOB and UAF in pdfium lcms
$7,000
7/9/2026
Heap-use-after-free in VerticalTabDragHandlerImpl::ContinueDrag
$1,000
7/9/2026
V8 Sandbox Bypass: Fast API overload metadata corruption causes compiler-emitted mixed native call type confusion
$5,000
7/9/2026
Extensions without file URL access can use the `Page.navigate` CDP command to open `view-source:file:` URLs
$2,000
7/9/2026
heap-use-after-free in XNNPACK widen_fp16_accumulators
$43,000
7/9/2026