Disclosed Chromium Security Bugs
←Back to Dashboardipcz bug can allow renderer duplicate browser process handle to escape sandbox
$250,000
8/6/2025
Improper Error Handling in LateLoadElimination for String Map in Turboshaft Leads to RCE
$50,000
7/11/2025
Arbitrary Wasm type confusion due to transient canonical index overflow
$62,000
6/17/2025
Signal SIGTRAP in v8
$55,000
6/11/2025
WasmCode "resurrection" using the WasmImportWrapperCache can lead to JIT allocation UaF, causing memory corruption
$55,000
5/10/2025
Incorrect WriteBarrier Optimization in ObjectAssign FastPath Leads to Exploitable UAF Vulnerability
$50,000
5/8/2025
WebAssembly out-of-bounds memory access due to broken memory64 guard page assumptions
$55,000
4/18/2025
WasmGCTypeAnalyzer improperly revisits single-block loops, leading to type confusion
$55,000
4/11/2025
Incorrect node replacement optimization during Maglev graph construction leads to RCE
$50,000
4/11/2025
AddressSanitizer:heap-use-after-free on LanguageDetectionModel::NotifyModelLoaded
$50,000
3/18/2025