Disclosed Chromium Security Bugs
←Back to DashboardV8 Sandbox Bypass: Compiler-Eliminated CPT Tag Check
$20,000
8/4/2026
Missing lifetime check in SpdyStream::IncreaseRecvWindowSize leads to use-after-free in Network Service
$43,000
8/4/2026
D3D10Warp!JITCopyContext::ExecuteResourceCopy memory heap overflow based on Integer overflow in gpu
$17,000
8/4/2026
Validating Decoder Stale PACK_ALIGNMENT causes GPU Heap OOB Write
$43,000
8/1/2026
Turbolev: incorrent opcode effect modeling can lead to arbitrary code execution
$55,000
8/1/2026
Turboshaft: stale `PhiOp` replacement for Wasm arrays causes `array.len` bounds bypass and out-of-bounds array read/write
$55,000
7/31/2026
UAF in WebViewImpl::Minimize
$11,000
7/31/2026
V8 sandbox bypass: reuse unpublished WasmDispatchTable lead to reproduce of 483220222
$20,000
7/30/2026
[Linux] Cross-Thread Use-After-Free in FontLoader::openStream via Non-Owning MappedFontFile Cache
$11,000
7/30/2026
Renderer-to-GPU sandbox escape via Skia SPIR-V injection
$25,000
7/30/2026