Disclosed Chromium Security Bugs
←Back to Dashboardmemory corruption in qualcomm gpu lead sandbox escape
$5,000
8/19/2026
Qualcomm Wild exploited CVE-2025-27038 bypass
$250,000
8/19/2026
Update Poc: Container-Overflow in `SurfaceAllocationGroup::OnFirstSurfaceActivation` due to reentrant mutation of `active_embedders_` in GPU process
$3,000
8/19/2026
V8 Sandbox Escape: Stale MicrotaskQueue cache leads to OOS write
$20,000
8/19/2026
WebGL Fullscreen Security UI Bypass
$1,000
8/19/2026
SpdyStream Use-After-Free in QueueNextDataFrame via PrefacePing drain
$43,000
8/18/2026
Turboshaft WLE correctness bug: stale StringPrepareForGetCodeUnit result survives calls, leaks V8 heap pointers via charCodeAt
$1,000
8/18/2026
A crafted GLSL ES 3.0 shader triggers an AST transformation bug in ANGLE's shared compiler frontend that produces an internally inconsistent AST (dangling variable references).
$2,000
8/15/2026
Reentrant socket destruction during ThrottlingP2PNetworkInterceptor timer callback leads to heap-use-after-free in the Network Service (browser process on Android)
$5,000
8/15/2026
Heap OOB read in ANGLE D3D11 backend via `GL_RGBX8_ANGLE` row pitch mismatch between validation and texture upload
$3,000
8/14/2026