Disclosed Chromium Security Bugs
←Back to DashboardHeap Buffer Overflow (READ) in TFLite + XNNPack via WebNN
$43,000
5/30/2026
ANGLE Vulkan reinitImageAsRenderable uint32 Overflow causes GPU OOB Write
$33,000
5/30/2026
Heap OOB read in SpeechRecognizerImpl::AddAudioFromRenderer
$36,000
5/29/2026
Heap Buffer Overflow in TFLite + XNNPack via WebNN
$33,000
5/29/2026
Heap-buffer-overflow in CSSUnparsedValue::FindVariableName
$11,000
5/29/2026
Security: Heap-use-after-free in SecureChannelImpl::OnDecryptedResponse
$11,000
5/29/2026
V8: Instruction Stream Corruption in Sparkplug+ via Missing `is_short_builtin_calls_enabled()` Guard in `Runtime_PatchLoadICUninitializedBaseline`
$11,000
5/27/2026
Security Check failed: Cannot create a handle without a HandleScope in v8::HandleScope::CreateHandle()
$8,000
5/26/2026
V8: Integer Truncation in Turboshaft PhiOp input_count via WASM br_table
$11,000
5/24/2026
UAF in ModelContext::ForEachScriptTool
$10,000
5/23/2026