Disclosed Chromium Security Bugs
←Back to DashboardANGLE Metal Shadow Buffer Stale Size causes GPU OOB WRITE
$18,000
7/10/2026
Maglev: unsound node replacement when inlining can lead to exploitable write barrier omission
$55,000
7/10/2026
UAF in Metal LibraryCache
$16,000
7/10/2026
Integer overflow in TFLite StridedSlice output dimension computation leads to heap buffer overflow in the GPU process
$43,000
7/9/2026
OOB and UAF in pdfium lcms
$7,000
7/9/2026
V8 Sandbox Bypass: Fast API overload metadata corruption causes compiler-emitted mixed native call type confusion
$5,000
7/9/2026
heap-use-after-free in XNNPACK widen_fp16_accumulators
$43,000
7/9/2026
V8: Signed Integer Overflow in Maglev ValueNode use_count_
$5,000
7/9/2026
FrameState: polymorphic Wasm accessor lazy deopt type confusion lead to in-sandbox corruption
$10,000
7/8/2026
Integer overflow in ANGLE D3D11 TextureStorage11::setData() leads to heap buffer overflow via WebGL2
$5,000
7/8/2026