Disclosed Chromium Security Bugs

setHTML() fails open on invalid SanitizerConfig, inserting unsanitized HTML with active scripts into the live DOM

#496524586Reporter: qw...@gmail.com
$2,000
7/10/2026

ANGLE Metal Shadow Buffer Stale Size causes GPU OOB WRITE

#492249619Reporter: ci...@gmail.com
$18,000
7/10/2026

Maglev: unsound node replacement when inlining can lead to exploitable write barrier omission

#493534950Reporter: pj...@gmail.com
$55,000
7/10/2026

UAF in Metal LibraryCache

#497724490Reporter: he...@gmail.com
$16,000
7/10/2026

Integer overflow in TFLite StridedSlice output dimension computation leads to heap buffer overflow in the GPU process

#495864183Reporter: je...@gmail.com
$43,000
7/9/2026

OOB and UAF in pdfium lcms

#498284498Reporter: he...@gmail.com
$7,000
7/9/2026

Heap-use-after-free in VerticalTabDragHandlerImpl::ContinueDrag

#490588145Reporter: ch...@gmail.com
$1,000
7/9/2026

V8 Sandbox Bypass: Fast API overload metadata corruption causes compiler-emitted mixed native call type confusion

#492077213Reporter: gu...@gmail.com
$5,000
7/9/2026

Extensions without file URL access can use the `Page.navigate` CDP command to open `view-source:file:` URLs

#491766258Reporter: al...@gmail.com
$2,000
7/9/2026

heap-use-after-free in XNNPACK widen_fp16_accumulators

#495864169Reporter: ki...@gmail.com
$43,000
7/9/2026
Showing 1-10 of 1936 bugs