1485446 | Security: Android: URL spoofing in address bar if scheme is later in URL | $8,500 | 2023-12-31 |
1484894 | DCHECK failure in begin.valid() in graph.h | - | 2023-12-30 |
1485549 | media_h265_parser_fuzzer: Stack-buffer-overflow in media::H265Parser::ParseVPS | - | 2023-12-30 |
1485583 | media_h265_decoder_fuzzer: Stack-buffer-overflow in media::H265Parser::ParseVPS | - | 2023-12-30 |
1485763 | Heap-use-after-free in base::ScopedObservation<ash::SessionController, ash::SessionObserver>::Reset | - | 2023-12-30 |
1484895 | DCHECK failure in !can_be_invalid implies result.valid() in optimization-phase.h | - | 2023-12-29 |
1485703 | Crash in v8::internal::Simulator::LoadStoreHelper | - | 2023-12-29 |
1448707 | sql_built_in_recovery_fuzzer: Incorrect-function-pointer-type in sqlite3ParseObjectReset | - | 2023-12-28 |
1472943 | Security: heap-use-after-free in vkr_ring_start | $5,000 | 2023-12-28 |
1483970 | Security: Chrome OS cros_camera_service UAF in mojo Camera3DeviceOps interface | - | 2023-12-28 |
1484000 | Security: UAF in cast_channel::CastSocketServiceImpl::OpenSocket | $1,000 | 2023-12-28 |
1483194 | Security: Container-Overflow in chrome_pdf::PDFiumRange::GetScreenRects | $1,000 | 2023-12-27 |
1478470 | mediasource_MP2T_AACLC_pipeline_integration_fuzzer: Trap in std::__Cr::__libcpp_verbose_abort | - | 2023-12-26 |
1482045 | URL Spoofing in Document PiP; related to issue 1450376; regression? | $500 | 2023-12-26 |
1483834 | client_side_phishing_fuzzer: Crash in safe_browsing::Scorer::ComputeRuleScore | - | 2023-12-26 |
1470827 | Security: virglrenderer | heap-buffer-overflow on vrend_decode_set_debug_mask | $2,000 | 2023-12-25 |
1471158 | Security: virglrenderer | heap-buffer-overflow on vrend_set_constants | $4,000 | 2023-12-25 |
1474640 | security: libmbim | heap-buffer-overflow on mbim-message.c | $750 | 2023-12-25 |
1478150 | Security: Cookie leaking from the request object in chrome.devtools.network in onRequestFinished event | $500 | 2023-12-25 |
1478889 | Security: Use-After-Free in PasswordManagerPorter::FileSelectionCanceled | $3,000 | 2023-12-25 |
1478366 | Security: Pdfium heap-buffer-overflow in downsample_3_2() | $2,000 | 2023-12-23 |
1481063 | lightweight-heap-use-after-free : views::Checkbox::GetChecked | - | 2023-12-23 |
1483259 | DCHECK failure in !finished_phis in graph.h | - | 2023-12-23 |
1483319 | Use-of-uninitialized-value in heap::base::SlotCallbackResult v8::internal::Scavenger::ScavengeObject<v8::inter | - | 2023-12-23 |
1483436 | Crash in unsigned int v8::base::AsAtomicImpl<int>::Relaxed_Load<unsigned int> | - | 2023-12-23 |
1483482 | Crash in v8::internal::Scavenger::Finalize | - | 2023-12-23 |
1442191 | Security: Race Condition UAF in l2cap_le_command_rej | $500 | 2023-12-22 |
1453841 | Security: 1-byte OOB in LogParserSyslog::ParseInternal | - | 2023-12-22 |
1455605 | Security: Local privilege escalation & sandbox escaping via chromeos-6.1 kernel BUG (DirtyVMA) | $500 | 2023-12-22 |
1457269 | Security: Double-free in icu (icu_73::Locale::Locale) under OOM condition | - | 2023-12-22 |
1472370 | Avoid v8::GlobalValueMap<std::pair<ParkableStringImpl*, Resource*>,...> | - | 2023-12-22 |
1473952 | Security: Multiple data-races and concurrency hazards in WebUIOmniboxPopup. | - | 2023-12-22 |
1473956 | Security: Heap buffer overflow write due to bound check missing | $7,000 | 2023-12-22 |
1473957 | Security: Chrome Download UI Clickjacking | $3,000 | 2023-12-22 |
1474235 | Security: OOB read in TGSI_OPCODE_EMIT | $1,000 | 2023-12-22 |
1480181 | heap-buffer-overflow : metrics::TabStatsDataStore::OnTabRemoved | - | 2023-12-22 |
1480191 | heap-use-after-free : dawn::native::metal::Adapter::InitializeSupportedFeaturesImpl | - | 2023-12-22 |
1480498 | heap-use-after-free : nearby::chrome::OutputStreamImpl::DoClose | - | 2023-12-22 |
1482681 | WebNN: UAF issue of persistent buffer binding for DML operator initialization | - | 2023-12-22 |
1482719 | v8_wasm_streaming_fuzzer: Container-overflow in v8::internal::compiler::Int64Lowering::LowerGraph | - | 2023-12-22 |
1460025 | Security: Document PIP URL address spoofing using long about:blank URL | $5,000 | 2023-12-21 |
1478446 | Security: heap-use-after-free in vrend_destroy_surface | $4,000 | 2023-12-21 |
1464794 | Security: UaF in Mirroring | $3,000 | 2023-12-20 |
1471305 | RegisterURLSchemeAsNotAllowingJavascriptURLs can be bypassed by stopping a window.open on the about:blank page and using window.opener | - | 2023-12-20 |
1476952 | Security: Bypassing of security interstitials using devtools API | $2,000 | 2023-12-20 |
1479892 | Container-overflow in message_center::NotificationList::GetNotificationById | - | 2023-12-20 |
1480852 | Security: Use-After-Free in chrome_pdf::PdfViewWebPlugin::PrintEnd | $2,000 | 2023-12-20 |
1470512 | double free in viz::VizDebugger::CompleteFrame | - | 2023-12-19 |
1481179 | Abrt in v8::internal::__RT_impl_Runtime_Abort | - | 2023-12-19 |
1475909 | h265_bitstream_parser_fuzzer: Use-of-uninitialized-value in webrtc::H265SpsParser::ParseSpsInternal | - | 2023-12-18 |
1476468 | Security: Debug check failed: (result.ptr) != nullptr. | - | 2023-12-18 |
1480000 | Security: manipulating the cvs data | $500 | 2023-12-16 |
1470553 | Security: UAF in It2MeNativeMessagingHostLacros::OnSupportSessionStarted | $11,000 | 2023-12-15 |
1479274 | Security vulnerability in WebP | $10,000 | 2023-12-15 |
1480151 | DCHECK failure in id_ != kInvalidNodeId in maglev-ir.h | - | 2023-12-15 |
1480184 | heap-use-after-free : chrome_pdf::PdfViewWebPlugin::UpdateFocus | - | 2023-12-15 |
1478112 | Security: UAF in: gpu::raster::RasterDecoderImpl::Initialize | $15,000 | 2023-12-14 |
1479104 | Security: Dangling FixedArray pointer in Promise.any can lead to memory corruption (incomplete fix for CVE-2023-4355) | - | 2023-12-14 |
1479713 | Dangling pointer in FedCmModalDialogView::ClosePopupWindow | - | 2023-12-14 |
1471330 | Security: type assertion fail in v8 | - | 2023-12-13 |
1475944 | h265_bitstream_parser_fuzzer: Trap in rtc::webrtc_checks_impl::WriteFatalLog | - | 2023-12-13 |
1478091 | Heap-buffer-overflow in Pass::blur | - | 2023-12-13 |
1474253 | Security: UAF in UnblockPendingSubframeNavigationRequestsIfNeeded | $1,000 | 2023-12-12 |
1475798 | Security: heap-use-after-free in mojo::StringDataSource::Read | $2,000 | 2023-12-09 |
1395164 | Security:Bypass the Protection of input fields cache (Autofill) 1358647 | $6,000 | 2023-12-08 |
1476190 | ax_tree_fuzzer: Trap in ui::AXTree::Unserialize | - | 2023-12-08 |
1477075 | Security: WebRTC PacketRouter Dangling Entry via Cross-Track SIM Group SSRC Collision | - | 2023-12-08 |
1477588 | Abrt in v8::internal::__RT_impl_Runtime_Abort | - | 2023-12-08 |
1447237 | Security: Chrome for Android Slowdown with JS then Navigate able to Hide Omnibox | $7,500 | 2023-12-07 |
1472365 | Avoid WTF::HashMap<RecordId, ImageInfo> | - | 2023-12-07 |
1472366 | Avoid WTF collections containing RecordId | - | 2023-12-07 |
1472372 | heap-buffer-overflow in StringForwardingTable::UpdateAfterFullEvacuation | $7,000 | 2023-12-07 |
1475959 | Security: stack-use-after-scope in base::trace_event::TraceArguments::CopyStringsTo | - | 2023-12-06 |
1476373 | Security: V8: Fatal error in ../../src/objects/property-array-inl.h | $7,000 | 2023-12-06 |
1471253 | Security: Cookie for enterprise-policy blocked hosts leaking from the request object in chrome.devtools.network. | $500 | 2023-12-05 |
1472029 | Trap in Builtins_CheckTurboshaftFloat64Type | - | 2023-12-05 |
1472367 | Avoid WTF::Deque<ConstraintsPair> | - | 2023-12-05 |
1473193 | Security: UAP in IDBFactory::DidAllowIndexedDB | $8,000 | 2023-12-05 |
1474174 | DCHECK failure in this->value_input_count(node) == 1 in instruction-selector.cc | - | 2023-12-05 |
1474285 | Security: V8 SEGV_ACCERR 02b6beadbef2 | $5,000 | 2023-12-05 |
1474312 | CHECK failure: maybe_code.has_value() in heap.cc | - | 2023-12-05 |
1475187 | UAF in blink::IDBFactoryClient::DeleteSuccess | $2,000 | 2023-12-05 |
1475637 | UAF in WTF::String | - | 2023-12-05 |
1475885 | Trap in Builtins_CheckTurboshaftFloat64Type | - | 2023-12-05 |
1476664 | DCHECK failure in gc_epilogue_callbacks_.IsEmpty() in local-heap.cc | - | 2023-12-05 |
1189131 | Chromium illegally paints outside of iframe when using -webkit-box-reflect | $1,000 | 2023-12-04 |
1458934 | Security: Bypass Spoofing download domain Chrome Windows | $1,000 | 2023-12-03 |
1472368 | Avoid ui::AXTreeSerializer<AXObject*> | - | 2023-12-03 |
1476164 | CHECK failure: page->SweepingDone() | - | 2023-12-03 |
1476265 | Crash in v8::internal::PagedSpaceBase::RefillFreeList | - | 2023-12-03 |
1469928 | Security: Use After Free in NetworkStateNotifier | $11,000 | 2023-12-01 |
1470992 | UAF in webrtc::SctpDataChannel::UpdateState (WEBRTC) | $10,000 | 2023-12-01 |
1472492 | Use-After-Free in MediaStreamDeviceObserver::OnDeviceStopped | $3,000 | 2023-11-29 |
1473961 | Crash in v8_internal_simulator_ProbeMemory | - | 2023-11-29 |
1472558 | Inadequate Registry management within the Chrome uninstaller resulting in privilege escalation | $3,000 | 2023-11-28 |
1425355 | Security: Intent URLs also bypass CSP sandbox with "allow-popups" set | $1,000 | 2023-11-27 |
1455587 | sql_recovery_fuzzer: Trap in std::__Cr::__libcpp_verbose_abort | - | 2023-11-26 |
1472966 | Security: Experimental features: Type assertion failed! (value/expectedType/nodeId) | - | 2023-11-25 |
1473389 | DCHECK failure in i_isolate->has_pending_exception() || thrower.error() in wasm-js.cc | - | 2023-11-24 |
1473631 | Security: CSA_DCHECK failed: Torque assert 'Is<A>(o)' failed | $16,000 | 2023-11-24 |
1463903 | Security: ChromeOS: Information leak due to type confusion in u32 classifier | $750 | 2023-11-23 |
1467666 | Security: Potential Design Flaw in Service Worker Lifecycle Management within Performance Manager | - | 2023-11-23 |
1468442 | Security: heap-use-after-free in vkr_context_submit_fence | $2,000 | 2023-11-23 |
1472173 | Security: UAF in SimpleHostResolverImpl::ResolveHost with chrome | $7,000 | 2023-11-23 |
1472317 | DCHECK failure in enum_length > 0 in keys.cc | - | 2023-11-23 |
1472364 | Avoid std::vector<Node*> | - | 2023-11-23 |
1472174 | DCHECK failure in kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)) in tagged-impl.h | - | 2023-11-22 |
1472318 | DCHECK failure in (location_) != nullptr in handles.cc | - | 2023-11-22 |
1472618 | DCHECK failure in !i_isolate->has_scheduled_exception() in wasm-js.cc | - | 2023-11-22 |
1472696 | Crash in v8::internal::VerifyPointersVisitor::VerifyPointers | - | 2023-11-22 |
1066555 | Security: tel: URL scheme reference origin spoof on Android Chrome | $500 | 2023-11-21 |
1414936 | Security: Android file picker dialog can be shown over a different tab | $5,000 | 2023-11-20 |
1453927 | Security: Chrome OS: Buffer overflow in function parse_raw_formats of venus driver | $500 | 2023-11-20 |
1453934 | Security: Chrome OS: Heap Buffer OOB write in function init_codecs of venus driver | $500 | 2023-11-20 |
1453935 | Security: Chrome OS: Multiple Heap Buffer OOB write bugs in venus driver because of reenter in hfi_parser function | $500 | 2023-11-20 |
1453937 | Security: Chrome OS: OOB write in function session_get_prop_buf_req of venus driver | $500 | 2023-11-20 |
1454624 | Security: Chrome OS: OOB read and write in venus_read_queue and venus_write_queue of venus driver | - | 2023-11-20 |
1468848 | Security: stack-use-after-return in tint::wgsl::writer::ASTPrinter::EmitStructType | $11,000 | 2023-11-20 |
1470539 | [zlib][fix] Heap overflow in minizip library (part of zlib) | - | 2023-11-20 |
1451543 | Security: Spoof empty titlebar via javascript: URI in Document PIP | $2,000 | 2023-11-18 |
1455619 | Security: Heap over read in libwebp WebPEncode (with lossless / alpha) under OOM condition | - | 2023-11-18 |
1469542 | UAF in rx::vk::DynamicDescriptorPool::destroyCachedDescriptorSet | $10,000 | 2023-11-18 |
1357442 | Security: Draw Mouse Cursor to hide omni box | $1,000 | 2023-11-17 |
1443147 | Security: Chrome iOS | $1,000 | 2023-11-17 |
1443214 | Security: On Chrome OS, any webpage is able to interface with the Chrome Goodies extension | - | 2023-11-17 |
1443571 | Security: Chrome iOS | $1,000 | 2023-11-17 |
1470668 | Security: Out-of-bounds access in ReduceJSLoadPropertyWithEnumeratedKey | - | 2023-11-17 |
1472121 | DCHECK failure in static_cast<unsigned>(index) < static_cast<unsigned>(this->length(kAcquireLoad)) | - | 2023-11-17 |
1451680 | Security: OOB in vb2ops_venc_queue_setup | $500 | 2023-11-16 |
1470522 | Memory corruption in Timeline | - | 2023-11-16 |
1467146 | Security: error json-stringifier.cc:1337 | - | 2023-11-15 |
1469754 | Security: Heap-use-after-free in blink::ThrottlingURLLoader::OnReceiveResponse | $3,000 | 2023-11-15 |
1470477 | Security: stack-use-after-scope | $2,000 | 2023-11-15 |
1464456 | XSS on chrome://file-manager, abusable by extensions | $5,000 | 2023-11-14 |
1465203 | XSS on Image Loader extension and chrome://resources, abusable by extensions to access private APIs | $5,000 | 2023-11-14 |
1467093 | Stack-buffer-overflow in v8::internal::JsonStringifier::SerializeString | - | 2023-11-14 |
1470434 | Security: Debug check failed: HasBytecodeArray() | $2,000 | 2023-11-14 |
1470448 | Security: Crash in v8::internal::OrderedHashTable<v8::internal::OrderedHashSet, 1>::Rehash | - | 2023-11-14 |
1468717 | DCHECK failure in type == MachineType::Int32() || type == MachineType::Uint32() || type.representa | - | 2023-11-13 |
1469909 | Security: wrong hole check against property cells | - | 2023-11-13 |
1470495 | DCHECK failure in load.outputs_rep()[0] == Asm().output_graph().Get(replacement).outputs_rep()[0 i | - | 2023-11-13 |
1469348 | freetype_colrv1_fuzzer: UNKNOWN READ in tt_face_load_colr | - | 2023-11-12 |
1430867 | Permission Tapjacking Is Possible In Android Custom Tabs | $3,000 | 2023-11-11 |
1435669 | UAF in ScrollableShelfView::shelf_container_view_ | - | 2023-11-11 |
1448548 | Security: UAF in AcquireFileAccessPermissionDoneForScheduleDownload | $30,000 | 2023-11-11 |
1464137 | Race Condition UAF in DRM_IOCTL_MODE_ATOMIC | - | 2023-11-11 |
1464511 | Chrome Custom Tab No Longer Tied to Parent App | - | 2023-11-11 |
1467921 | Security: heap-use-after-free on ash/wm/desks/desks_controller.cc | $3,000 | 2023-11-11 |
1468813 | Security: heap-use-after-free on ash/wm/overview/overview_item.cc | $3,000 | 2023-11-11 |
1469800 | Security: Type cast failed in v8 | $8,000 | 2023-11-11 |
1470166 | DCHECK failure in MachineRepresentation::kTagged == type.representation() in code-generator.cc | - | 2023-11-11 |
1316379 | Security: Heap Buffer Overflow in mojo Message | $1,000 | 2023-11-09 |
1454515 | Security: Cursor hijacking mitigation bypass if iframe's content area is outside the top-layer content area | $2,000 | 2023-11-09 |
1464215 | Security: SKIA: integer overflow in sk_path_analyze_verbs. | - | 2023-11-09 |
1465833 | Security: heap-use-after-free in network::NetworkContext::DestroyURLLoaderFactory | $2,000 | 2023-11-09 |
1466415 | Security: Heap-use-after-free in HostResolverManager::Job::RunNextTask | $3,000 | 2023-11-09 |
1467743 | Security: chrome.devtools.inspectedWindow.getResources allows resources from enterprise policy-blocked hosts | $500 | 2023-11-09 |
1468458 | Security: Debug check failed: page->area_size() >= static_cast<size_t>(page->live_bytes()) | $10,000 | 2023-11-09 |
1468943 | Security: Dangling FixedArray pointers in Torque lead to memory corruption | - | 2023-11-09 |
1469534 | Debug check failed: IsKind(TypeBase::kWasm) in WasmLoadElimination::HalfState::KillField | - | 2023-11-09 |
1398996 | Security: ChromeOS wpa_supplicant arbitrary shared object load | - | 2023-11-08 |
1406165 | Security: Race Condition UAF in i915_perf_add_config_ioctl | $16,000 | 2023-11-08 |
1421706 | Security: Race Condition UAF in mtk_jpeg_job_timeout_work | $5,000 | 2023-11-07 |
1454817 | Security: Users cannot escape the full screen mode in this offline .html file | $3,000 | 2023-11-07 |
1455857 | potential victim of Spectre in intel_pxp_sm_ioctl_terminate_session | - | 2023-11-07 |
1456561 | Race Condition UAF in amdgpu_cs_wait_fences_ioctl | $1,000 | 2023-11-07 |
1458807 | Security: Chrome OS : Multiple bugs in cros_gralloc | $1,000 | 2023-11-07 |
1459182 | Security: Use-After-Free in NFT_MSG_NEWRULE | - | 2023-11-07 |
1462551 | Security: Chrome OS : Two security bugs of mwifiex | $1,500 | 2023-11-07 |
1463447 | Extensions can open chrome-untrusted:// URLs with identity.launchWebAuthFlow | $750 | 2023-11-07 |
1464445 | Security: Chrome OS: bluez missed patch can cause remotely information leak in function cli_feat_read_cb | $500 | 2023-11-07 |
1467751 | Security: chrome.devtools.inspectedWindow.eval can bypass enterprise-policy blocked hosts using subframes | $500 | 2023-11-07 |
1468886 | Uaf in OmniboxPopupPresenter::WaitForHandler | $2,000 | 2023-11-07 |
1464449 | UAF in gsm_cleanup_mux | $1,500 | 2023-11-06 |
1465224 | net_quic_stream_factory_fuzzer: Heap-use-after-free in net::QuicChromiumClientStream::Handle::ReadBody | - | 2023-11-06 |
1468148 | Security: v8 error Received signal 11 SEGV_MAPERR 000000000dd0 | - | 2023-11-06 |
1468901 | Security: LoadPropertyFromGlobalDictionary checks the wrong hole | - | 2023-11-06 |
1458046 | Security: [GPU/Angle] heap-buffer-overflow WRITE of size 496 [@rx::PackPixels] | - | 2023-11-04 |
1467554 | Trap in Builtins_CheckTurboshaftWord32Type | - | 2023-11-03 |
1449166 | Fatal error in #41:Dead should be followed by IfSuccess/IfException, but is only followed by si | - | 2023-11-02 |
1458303 | Security: Heap-use-after-free in KeyRotationLauncherImpl::SynchronizePublicKey | $5,000 | 2023-11-02 |
1462723 | Security: Eyedropper API can confuse real cursor position which can cause users to be tricked into clicking unwanted positions (ie. accepting permission prompts) | $2,000 | 2023-11-02 |
1467142 | Security: V8: Debug check failed: result_type.IsSubtypeOf(output_graph_types_[index]). | $7,000 | 2023-11-02 |
1467622 | UAF in raw_ptr with FedCM IDP Signin status | - | 2023-11-02 |
1465230 | [Autofill] Keyboard accessory, bottom sheet accept unintentional user input | $2,000 | 2023-11-01 |
1466124 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in marl::Scheduler::Worker::run | - | 2023-11-01 |
1466128 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in marl::Scheduler::Worker::runUntilIdle | - | 2023-11-01 |
1467157 | Security: Heap-use-after-free in GetAuthorizationRightsWithPrompt | $3,000 | 2023-11-01 |
1467169 | Security: Extension Has Access to File URL Despite Access is Disabled | $5,000 | 2023-11-01 |
1453507 | Security: Multiple cros_ec bugs when handling host commands from Application Processor | $500 | 2023-10-31 |
1458291 | Security: V8: Fatal error in ../../src/api/api-inl.h, line 55 | $7,000 | 2023-10-31 |
1459281 | Security: about:blank origin shown in Bluetooth and other permission dialogs | $3,000 | 2023-10-31 |
1467471 | DCHECK failure in kind.tagged_base ? ValidOpInputRep(graph, base(), RegisterRepresentation::Tagged | - | 2023-10-31 |
1423266 | Security: ChromeOS: Local privilege escalation due to use-after-free in u32 classifier | - | 2023-10-30 |
1447376 | Security: Race Condition UAF in hci_remove_ltk | $6,000 | 2023-10-30 |
1464636 | Security: UAF in VisualSearchClassifierHost::StartClassificationWithModel | $3,000 | 2023-10-30 |
1467028 | DCHECK failure in !maybe_outer_scope_info.is_null() in parser.cc | - | 2023-10-30 |
1449874 | Security: Bypass the Protection of input fields cache (Autofill) due to inappropriate code design (Bypass 1108181) | $6,000 | 2023-10-29 |
1412965 | Security: use of uninitialized member variable in omnibox_popup_view_views.cc:575 | $4,000 | 2023-10-28 |
1455964 | Security: persistent and arbitrary pip2 window | - | 2023-10-28 |
1441228 | Security: Select option can cover permission buble , lead to spoof | $500 | 2023-10-27 |
1463293 | Security: interstitials with one click to proceed are clickjackable | - | 2023-10-27 |
1466183 | Security: Memory corrupt in v8, leading to RCE | $23,000 | 2023-10-27 |
1466315 | DCHECK failure in mode == FastCloneObjectMode::kIdenticalMap implies !map->is_prototype_map() in i | - | 2023-10-27 |
1466543 | DCHECK failure in descriptor_number.as_int() < number_of_descriptors() in descriptor-array-inl.h | - | 2023-10-27 |
1466785 | DCHECK failure in details.kind() == PropertyKind::kData in ic.cc | - | 2023-10-27 |
1444766 | Security: A use after free vulnerability exists in ChromeOS Kernel | $15,000 | 2023-10-25 |
1456243 | Security: [ANGLE] opengl : Out-of-bounds memory can be accessed using offsets in vertexAttribPointer | $10,000 | 2023-10-25 |
1464038 | I'm reporting an incomplete fix for a prior report (1451211) and (1427865). | $15,000 | 2023-10-25 |
1465326 | Security: Type confusion in VisitFindNonDefaultConstructorOrConstruct of Maglev | $21,000 | 2023-10-25 |
1215629 | Security: stack-buffer-overflow WRITE of size 169 while parsing a file in espeak-ng (ChromeOS relevant) | - | 2023-10-24 |
1215641 | Security: heap-use-after-free READ of size 4 while parsing a file in espeak-ng (ChromeOS relevant) | - | 2023-10-24 |
1215645 | Security: stack-buffer-overflow READ of size 1 while parsing a file in espeak-ng (ChromeOS relevant) | - | 2023-10-24 |
1215650 | Security: stack-buffer-overflow WRITE of size 494 while parsing a file in espeak-ng (ChromeOS relevant) | - | 2023-10-24 |
1215660 | Security: stack-buffer-overflow READ of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215664 | Security: stack-buffer-overflow READ of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215672 | Security: heap-buffer-overflow READ of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215678 | Security: global-buffer-overflow WRITE of size 4 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215752 | Security: heap-use-after-free READ of size 4 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215756 | Security: global-buffer-overflow WRITE of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215761 | Security: stack-buffer-overflow WRITE of size 62 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215768 | Security: heap-use-after-free READ of size 4 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215772 | Security: stack-buffer-overflow READ of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215774 | Security: stack-buffer-overflow READ of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215781 | Security: heap-use-after-free READ of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215783 | Security: heap-use-after-free READ of size 4 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215789 | Security: heap-use-after-free READ of size 4 while parsing a file in espeak-ng (ChromeOS relavant | - | 2023-10-24 |
1215794 | Security: global-buffer-overflow WRITE of size 4 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215797 | Security:stack-buffer-overflow READ of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215800 | Security: stack-buffer-overflow READ of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215806 | Security: stack-buffer-overflow WRITE of size 1 while parsing a file in espeak-ng (ChromeOS relavant) | - | 2023-10-24 |
1215820 | Security: stack-buffer-overflow WRITE of size 420 while parsing a file in espeak-ng (ChromeOS relevant) | - | 2023-10-24 |
1216020 | Security: espeak-ng memory vulnerabilities | $1,000 | 2023-10-24 |
1458911 | Security: Libxslt arbitrary file reading using document() method and external entities. | $3,000 | 2023-10-24 |
1459124 | Security: prevent ssrc-related SDP munging | - | 2023-10-24 |
1464680 | Security: Incomplete fix for 1431761 | - | 2023-10-24 |
1465120 | DCHECK failure in is_activated_ || shared_heap_worklist_.has_value() in marking-barrier.cc | - | 2023-10-24 |
1465193 | Security: Memory corruption due to HeapVector iterator invalidation | $4,000 | 2023-10-24 |
1465293 | Security: Heap-use-after-free in BrowsingTopicsServiceImpl::GetBrowsingTopicsStateForWebUi | $2,000 | 2023-10-24 |
1395323 | Security: ChromeOS Guest User Can Force Persistent Rollback on Stable Channel | - | 2023-10-23 |
1454328 | Security: Out of bound in intel_pxp_sm_ioctl_query_pxp_tag | $1,250 | 2023-10-23 |
1455270 | Security: Heap-use-after-free in ui::PropertyHandler::GetPropertyInternal | $2,000 | 2023-10-23 |
1464516 | Security: v8 Fatal error in ../../src/objects/tagged-impl-inl.h, line 213 | - | 2023-10-23 |
1465130 | Security: Debug check failed: !s.InSharedHeap(). | $7,000 | 2023-10-23 |
1465300 | Crash in Builtins_ArrayPrototypeJoin | - | 2023-10-23 |
1465342 | DCHECK failure in page->area_size() >= static_cast<size_t>(page->live_bytes()) in sweeper.cc | - | 2023-10-23 |
1465347 | Crash in v8::internal::ConcurrentMarking::JobTaskMajor::Run | - | 2023-10-23 |
1465350 | Crash in Builtins_ArrayIteratorPrototypeNext | - | 2023-10-23 |
1465351 | Crash in void v8::internal::String::WriteToFlat<unsigned char> | - | 2023-10-23 |
1465352 | Crash in Builtins_KeyedLoadIC | - | 2023-10-23 |
1465356 | Crash in void v8::internal::String::WriteToFlat<unsigned char> | - | 2023-10-23 |
1465358 | CHECK failure: result->IsValue() | - | 2023-10-23 |
1465359 | Crash in void v8::internal::String::WriteToFlat<unsigned char> | - | 2023-10-23 |
1465362 | CHECK failure: space->Contains(index) | - | 2023-10-23 |
1465365 | Crash in v8::internal::Runtime_RunMicrotaskCallback | - | 2023-10-23 |
1465368 | Crash in v8::internal::Map::visitor_id | - | 2023-10-23 |
1465370 | CHECK failure: storage_.is_populated_ | - | 2023-10-23 |
1465374 | CHECK failure: IsContext() | - | 2023-10-23 |
1465375 | Crash in v8::internal::RecordMigratedSlotVisitor::RecordMigratedSlot | - | 2023-10-23 |
1465377 | Crash in Builtins_MapPrototypeSet | - | 2023-10-23 |
1422272 | Security: Using popups, Incognito Mode-specific external protocol prompts can be overlaid on other origins on Android. | $500 | 2023-10-21 |
1458819 | Security: Heap-buffer-overflow in CompositorFrameSinkSupport::DidPresentCompositorFrame | $17,000 | 2023-10-21 |
1464734 | Use-after-poison in blink::MessagePort::~MessagePort | - | 2023-10-21 |
1421349 | Security: stack OOB in xfrm_state_find | $1,000 | 2023-10-20 |
1457049 | Security: SoftNavigation + first-paint can leak history information | $5,000 | 2023-10-20 |
1462104 | Incognito Mode Leaving Alert Dialog Box Tapjacking on DoubleClick | $2,000 | 2023-10-20 |
1463850 | Security: Segment Fault in v8 wasm at address > page size | $1,000 | 2023-10-20 |
1464324 | Security: Puppeteer's vm2 dependency has major security vuln | - | 2023-10-20 |
1464682 | Security: shouldLimitTypeSizes check bypassable from a compromised renderer | - | 2023-10-20 |
1464786 | DCHECK failure in !shared_heap_worklist_.has_value() in marking-barrier.cc | - | 2023-10-20 |
1431043 | Security: Picture in picture can hide fullscreen notification | $1,000 | 2023-10-19 |
1464008 | DCHECK failure in kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)) in tagged-impl.h | - | 2023-10-19 |
1464179 | CVE-2023-26966 and CVE-2023-2908 were fixed in libtiff and published but not propagated to Pdfium yet | - | 2023-10-19 |
1367085 | Security: Web Share dialog URL is incorrectly elided in Android (ineffective fix for issue 1329541) | $1,000 | 2023-10-18 |
1464080 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsHeapObject()) in heap- | - | 2023-10-18 |
1464231 | v8_wasm_fuzzer: Crash in v8::internal::RootScavengeVisitor::VisitRootPointer | - | 2023-10-18 |
1420130 | Security: [WebGL2/Mali] Heap-buffer-overflow in WebGL2 Shader compilation on Android | - | 2023-10-17 |
1457757 | UAF in media_router::IssuesObserver::~IssuesObserver() | $5,000 | 2023-10-17 |
1461969 | Race Condition UAF in KVM_DEV_VFIO_GROUP | $9,500 | 2023-10-17 |
1462501 | DCHECK failure in !HAS_WEAK_HEAP_OBJECT_TAG(ptr_) in tagged-impl-inl.h | - | 2023-10-17 |
1463134 | DCHECK failure in constant.is_int64() in instruction-selector-x64.cc | - | 2023-10-17 |
1463219 | DCHECK failure in index < parameter_count_ in signature.h | - | 2023-10-17 |
1463289 | DCHECK failure in end.valid() in graph.h | - | 2023-10-17 |
1463826 | DCHECK failure in chunk->Contains(slot_addr) in remembered-set.h | - | 2023-10-17 |
1451146 | chrome.devtools.inspectedWindow.reload can run scripts on the Chrome Web Store | $3,000 | 2023-10-16 |
1461895 | chrome.devtools.inspectedWindow origin limitations are very broken and can be bypassed | $1,000 | 2023-10-16 |
1462951 | Security: Type Confusion in V8 WebAssembly, leading to RCE | $20,000 | 2023-10-16 |
1463001 | pdfium_xfa_fuzzer: Container-overflow in CFDE_TextOut::RetrievePieces | - | 2023-10-16 |
1462937 | DCHECK failure in old_map->owns_descriptors() in js-objects.cc | - | 2023-10-14 |
1463218 | CHECK failure: IsEmpty() | - | 2023-10-14 |
1424415 | DCHECK failure in !space->IsInlineAllocationEnabled() implies space->limit() == space->top() in ru | - | 2023-10-13 |
1457095 | Security: use-after-free/data-race (in off-by-default JavaScriptExperimentalSharedMemory feature) | $10,000 | 2023-10-13 |
1449929 | Security: heap-use-after-free on AudioManagerWin | $5,000 | 2023-10-12 |
1453465 | Security: heap-use-after-free on chrome/browser/ui/views/tabs/tab_strip.cc:220:5 | $2,000 | 2023-10-12 |
1457472 | Security: Interactionfull Devtools UXSS | - | 2023-10-12 |
1457840 | Security: [ANGLE] metal : Out-of-bounds memory can be accessed on DrawCmd | $10,000 | 2023-10-12 |
1458955 | Heap-use-after-free in ui::AXTreeSerializer<blink::AXObject*>::AnyDescendantWasReparented | - | 2023-10-12 |
1460019 | v8_wasm_compile_fuzzer: Segv on unknown address in v8::internal::WasmInternalFunction::GetOrCreateExternal | - | 2023-10-12 |
1462527 | DCHECK failure in displacement != 0 in instruction-selector-x64.cc | - | 2023-10-12 |
1457131 | Security: webrtc: wildptr in VideoCaptureModulePipeWire::StopCapture() | - | 2023-10-11 |
1457421 | Security: UAF in webrtc::SctpDataChannel::SetState | $7,000 | 2023-10-11 |
1342896 | Security: UAF in PermissionAuditingService multiple functions | $4,000 | 2023-10-10 |
1454105 | Trap in Builtins_CheckTurboshaftFloat64Type | - | 2023-10-10 |
1454544 | New webstore domain needs to be added into the devtools extension API URL checks | - | 2023-10-10 |
1457717 | memory corruption in MarkCompactCollector::ProcessMarkingWorklist(v8) | $7,000 | 2023-10-10 |
1458837 | Crash in Builtins_StringEqual | - | 2023-10-10 |
1460177 | Use-of-uninitialized-value in v8::internal::JsonParser<unsigned char>::CalculateFileLocation | - | 2023-10-10 |
1459172 | Crash in Builtins_TypedArrayPrototypeMap | - | 2023-10-09 |
1404001 | Security: PWA Install prompt can be overlaid over other origins. | $4,000 | 2023-10-08 |
821625 | Data URL doesn't inherit CSP | $1,000 | 2023-10-06 |
821628 | CSP not inherited after navigation to JavaScript scheme URI (iOS) | $1,000 | 2023-10-06 |
821632 | CSP form-action seems to be ignored if target="_blank" | $1,000 | 2023-10-06 |
1458337 | CHECK failure: static_cast<uintptr_t>(caller_frame_top_) > stack_guard->real_jslimit() in deopt | - | 2023-10-06 |
1458376 | sequence_manager_fuzzer: Heap-use-after-free in base::sequence_manager::internal::TaskQueueImpl::TaskRunner::PostDelayedTask | - | 2023-10-06 |
1429353 | chrome.devtools.inspectedWindow.eval bypasses the ExtensionSettings policy | - | 2023-10-05 |
1458355 | Out of bounds read in oscillator_kernel_neon.cc | - | 2023-10-05 |
1459277 | Security: Out of bounds read due to a missing bounds check | - | 2023-10-05 |
1457802 | CHECK failure: Object::AddDataProperty(&it, context, attributes, Just(kDontThrow), StoreOrigin: | - | 2023-10-03 |
1455485 | Security: UaF in GpuImageDecodeCachePurgeOnTimerTest.SimplePurgeOneImage | - | 2023-10-02 |
1457745 | Trap in Builtins_CheckTurboshaftFloat64Type | - | 2023-10-02 |
1455706 | DCHECK failure in var.has_value() in optimization-phase.h | - | 2023-09-29 |
1427288 | Reloading the original request URL incorrectly uses NavigationEntry state with a different URL | - | 2023-09-28 |
1454086 | UAF in webrtc::DataChannelController::OnChannelStateChanged | $7,000 | 2023-09-28 |
1456853 | CHECK failure: !available->IsEmpty() in macro-assembler-arm64.h | - | 2023-09-28 |
1451286 | heap-use-after-free : ash::libassistant::GrpcServicesInitializer::~GrpcServicesInitializer | - | 2023-09-27 |
1455679 | DCHECK failure in !argument.IsTheHole() in elements.cc | - | 2023-09-27 |
1455959 | DCHECK failure in !value->properties().is_conversion() in maglev-interpreter-frame-state.h | - | 2023-09-27 |
1456617 | DCHECK failure in IsPrimitiveMap() || instance_type() == WASM_NULL_TYPE in map-inl.h | - | 2023-09-27 |
1447387 | Security: Right Click Prompt overlap autofill. , it can confuse lead to spoof | $500 | 2023-09-26 |
1451164 | Security: UAF in ash::diagnostics::AsyncLog::Append | $5,000 | 2023-09-26 |
1455797 | CHECK failure: predecessor in maglev-graph-builder.h | - | 2023-09-26 |
1342115 | Security: V8 Typer hardening bypass via ReduceArrayPrototypeAt | $5,000 | 2023-09-25 |
1453232 | DCHECK failure in source.IsValid() in js-heap-broker.cc | - | 2023-09-25 |
1453582 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsJSReceiver_NonInline(* | - | 2023-09-25 |
1455185 | CHECK failure: !available->IsEmpty() in macro-assembler-arm64.h | - | 2023-09-25 |
1455517 | DCHECK failure in !is_empty() in reglist-base.h | - | 2023-09-25 |
1455550 | DCHECK failure in bytecode_analysis().IsLoopHeader(offset) in maglev-graph-builder.h | - | 2023-09-25 |
1455641 | DCHECK failure in 1 == args.length() in runtime-collections.cc | - | 2023-09-25 |
1443292 | Security: adb wireless debugging bugfix bypass | $3,000 | 2023-09-22 |
1449007 | Security: Forced user interaction for Hidden permission prompts by freezing/resizing the browser Bypass of 1371215 | $3,000 | 2023-09-22 |
1453209 | Security: Heap-use-after-free in UploadToReportingServer | $3,000 | 2023-09-22 |
1454722 | Crash in blink::LayoutTreeBuilderTraversal::FirstChild | - | 2023-09-22 |
1454860 | WebRTC crashes on closing a peerconnection which munges the RTX ssrc to be the same as the primary SSRC | - | 2023-09-22 |
1455189 | DCHECK failure in IsStackSlot() || IsFPStackSlot() in instruction.h | - | 2023-09-22 |
1455238 | Crash in memfd:swiftshader_jit | - | 2023-09-22 |
1455318 | Crash in Builtins_InterpreterEntryTrampoline | - | 2023-09-22 |
1455359 | DCHECK failure in predecessor_count_ > 1 in maglev-interpreter-frame-state.cc | - | 2023-09-22 |
1348733 | Security: Dangling pointer in Dawn::Buffer | - | 2023-09-21 |
1412057 | sql_recovery_fuzzer: Crash in sql::recover::VirtualCursor::AppendPageDecoder | - | 2023-09-21 |
1449799 | Security: type mismatch with jit,0 vs 65536 | $7,000 | 2023-09-21 |
1454097 | Security: heap-buffer-overflow in vkr_dispatch_vkAllocateMemory | - | 2023-09-21 |
1454436 | DCHECK failure in ((immediate >> kWRegSizeInBits) == 0) || ((immediate >> kWRegSizeInBits) == -1) | - | 2023-09-21 |
1454478 | DCHECK failure in HasValue() in maglev-graph-builder.h | - | 2023-09-21 |
1449150 | freetype_truetype_render_fuzzer.exe: Int-overflow in T1_Face_Init | - | 2023-09-20 |
1449895 | Security: SEGV on emit_ios_generic_outputs | $7,000 | 2023-09-20 |
1451115 | Heap-use-after-free in ui::AXTreeSerializer<blink::AXObject*>::AnyDescendantWasReparented | $9,000 | 2023-09-20 |
1451999 | Crash in v8::internal::DependentCode::SetDependentCode | - | 2023-09-20 |
1452137 | Security: Type confusion in v8 caused by incorrect side effect modelling of JSStackCheck | $20,000 | 2023-09-20 |
1452254 | CHECK failure: !descriptors.GetKey(i).IsInteresting(isolate) in objects-debug.cc | - | 2023-09-20 |
1454726 | DCHECK failure in owner == interpreter::Register::current_context() implies IsResumableFunction( b | - | 2023-09-20 |
1443722 | Regression: External protocol confirmation dialog may overlap with other origins | $2,000 | 2023-09-19 |
1448729 | sqlite3_dbfuzz2_fuzzer: Use-of-uninitialized-value in cellSizePtrTableLeaf | - | 2023-09-19 |
1450809 | UAF in MarkingWorklists::Local::IsEmpty(v8) | $7,000 | 2023-09-19 |
1452076 | Security: Read-only property overwrite in TurboFan | - | 2023-09-19 |
1453973 | Security: Fatal error in ../../src/compiler/turboshaft/types.h | $7,000 | 2023-09-19 |
1168551 | Security: android-root privilege escalation | - | 2023-09-18 |
1413104 | Security: Race Condition UAF in hci_cmd_sync_work(2) | $4,000 | 2023-09-18 |
1423627 | Security: OOB Access in intel_pxp_sm_ioctl_mark_session_in_play | $16,000 | 2023-09-18 |
1424269 | Security: use after free in virtwl_ioctl_recv | - | 2023-09-18 |
1424270 | Security: out of bound read in vfd_out_locked | $1,000 | 2023-09-18 |
1441306 | Security: Calling ash::DiagnosticsDialog::ShowDialog multiple times can result in an Use-After-Free (UAF) error in ash::diagnostics::NetworkingLog::UpdateNetworkList. | $5,000 | 2023-09-18 |
1447372 | Security:Integer overflow in vn_decode_vkExecuteCommandStreamsMESA_args_temp | $7,000 | 2023-09-18 |
1447373 | Integer overflow in vkr_cs_encoder_set_stream | $7,000 | 2023-09-18 |
1447984 | Security: Chrome OS cros_camera_service UAF in mojo Camera3DeviceOps interface | - | 2023-09-18 |
1450118 | Security: OOB in NotificationDaemon::OnClicked | - | 2023-09-18 |
1451803 | Security : Heap UaF on ash/wm/splitview/split_view_divider_view.cc:168:23 | $3,000 | 2023-09-18 |
1453435 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in CmdBeginRenderPass::execute | - | 2023-09-18 |
1453608 | Security: Stack-use-after-return in BrowserAttestationService::OnChallengeValidated | $5,000 | 2023-09-18 |
1453781 | DCHECK failure in argc_value.IsSmi() in frames.cc | - | 2023-09-18 |
1453875 | Crash in v8::internal::ErrorUtils::Construct | - | 2023-09-18 |
1450203 | Security: PWA dialog can be triggered from malicious origin and shown over Trusted Origin(Spoofing) Bypassing Google Security Measures in Chrome UI | $5,000 | 2023-09-17 |
1453481 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in marl::Scheduler::Worker::run | - | 2023-09-17 |
1427861 | sql_recovery_fuzzer: Trap in std::Cr::__libcpp_verbose_abort | - | 2023-09-16 |
1434438 | Security: Custom Tab Scroll Inference | $2,000 | 2023-09-16 |
1438549 | Security: UAF in SaveUPIOfferBubbleViews::WindowClosing | $6,000 | 2023-09-15 |
1444438 | Security: destroying a SiteInstance can use-after-free the BrowserContext | - | 2023-09-15 |
1450899 | Security: IPCZ FragmentDescriptors are not validated. | - | 2023-09-15 |
1451338 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in marl::Scheduler::Worker::runUntilIdle | - | 2023-09-15 |
1451763 | lightweight-heap-use-after-free : ui::AXTree::Destroy | - | 2023-09-15 |
1447568 | Security: TALOS-2023-1751 - Google Chrome VideoEncoder av1_svc_check_reset_layer_rc_flag use-after-free vulnerability | $10,000 | 2023-09-14 |
1449678 | Security: heap-use-after-free on LibcastSocketService | $16,000 | 2023-09-14 |
1451957 | Security: CVE-2016-10195 | - | 2023-09-14 |
1450568 | Security: UAF in AutofillSnackbarController | $21,000 | 2023-09-13 |
1450771 | Security: v8 crash Bytecode mismatch at offset 78 | $7,000 | 2023-09-13 |
1450784 | Security: UAF in extensions::OffscreenCreateDocumentFunction::OnExtensionHostDestroyed (browser process) | $1,000 | 2023-09-13 |
1451275 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in marl::Scheduler::Worker::run | - | 2023-09-13 |
1451332 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in CmdBeginRenderPass::execute | - | 2023-09-13 |
1450114 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsSeqOneByteString_NonIn | $5,000 | 2023-09-12 |
1450397 | Security: UAF in guest_view::GuestViewManager::EmbedderProcessDestroyed(browser process) | $5,000 | 2023-09-12 |
1451056 | DCHECK failure in !is_compiled() || ActiveTierIsIgnition() || ActiveTierIsBaseline() || ActiveTier | - | 2023-09-12 |
1450330 | DCHECK failure in effect_edges > 0 in verifier.cc | - | 2023-09-11 |
1443540 | Security: `Sec-Browsing-Topics` exposes the number of topics sent to cross-site recipients | - | 2023-09-09 |
1447264 | gpu_swangle_passthrough_fuzzer.exe: Crash in vk::Queue::taskLoop | - | 2023-09-09 |
1449559 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in marl::Scheduler::Worker::runUntilIdle | - | 2023-09-09 |
1450376 | Security: Document PiP URL spoof | $5,000 | 2023-09-09 |
1450862 | DCHECK failure in last_position.IsKnown() in profiler-listener.cc | - | 2023-09-09 |
1445492 | Security: Heap-use-after-free in AboutThisSiteSidePanelView::HandleKeyboardEvent | $3,000 | 2023-09-08 |
1446274 | Security: UAF in webrtc::PeerConnection::ReportTransportStats() | $3,000 | 2023-09-08 |
1449912 | dawn_wire_server_and_vulkan_backend_fuzzer: Incorrect-function-pointer-type in marl_fiber_trampoline | - | 2023-09-08 |
1450142 | Security: [WebGPU] Dawn trusts function pointer from Renderer Process | - | 2023-09-08 |
1450481 | Security: [0-day] Bug in the handling of the arguments object | - | 2023-09-08 |
1450601 | Security: heap-use-after-free in device::OpenXrApiWrapper::InitSession | - | 2023-09-08 |
1449054 | DCHECK failure in (receiver_) != nullptr in scopes.h | - | 2023-09-07 |
1449589 | DCHECK failure in (BasicBlock::GetCommonDominator(block, user_block) == block) || (user_block->IsL | - | 2023-09-07 |
1449611 | CHECK failure: (chunk->slot_set<OLD_TO_NEW>()) == nullptr in heap-verifier.cc | - | 2023-09-07 |
1450395 | DCHECK failure in known_node_aspects().possible_maps[object].possible_maps.contains( map) in magle | - | 2023-09-07 |
1450443 | DCHECK failure in !ActiveTierIsTurbofan() in js-function.cc | - | 2023-09-07 |
1429999 | Security: Heap-use-after-free in SavedTabGroupButton::MoveGroupToNewWindowPressed | $3,000 | 2023-09-06 |
1446754 | Security: Bypass Of 1342072 | $2,000 | 2023-09-06 |
1447382 | v8_wasm_compile_fuzzer: Use-after-poison in v8::internal::wasm::LiftoffAssembler::SpillRegister | - | 2023-09-06 |
1448746 | pdf_codec_icc_fuzzer: Incorrect-function-pointer-type in cmsPipelineEval16 | - | 2023-09-06 |
1449085 | pdf_jpx_fuzzer: Incorrect-function-pointer-type in opj_setup_decoder | - | 2023-09-06 |
1449208 | DCHECK failure in HeapType(heap_type).is_valid() in value-type.h | - | 2023-09-06 |
1449540 | DCHECK failure in offset < length() in fixed-array-inl.h | - | 2023-09-06 |
1406922 | Security: Forced user interaction for permission prompts by closing a popup window | $1,000 | 2023-09-05 |
1449291 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsJSReceiver_NonInline(* | - | 2023-09-05 |
1449497 | Heap-use-after-free in net::HostResolverSystemTask::StartLookupAttempt | - | 2023-09-04 |
1446045 | Security: Omaha EoP on Windows via COM | - | 2023-09-02 |
1447363 | Security DCHECK failure: IsA<Derived>(from) in casting.h | - | 2023-09-02 |
1448032 | Security: Heap Buffer Overflow and Security DCHECK failed: IsA<Derived>(from) in MediaStreamTrackImpl::stopTrack | $11,000 | 2023-09-01 |
1426517 | Security: Heap-use-after-free in ash::DeskMiniView::UpdateDeskButtonVisibility | $1,000 | 2023-08-31 |
1438990 | DCHECK failure in all implies !none in maglev-graph-builder.cc | - | 2023-08-31 |
1441254 | Security:Debug check failed: HasBuiltinId() implies builtin_id() != Builtin::kCompileLazy. | $8,000 | 2023-08-31 |
1448041 | Debug check failed: Heap::InFromPage(object). | - | 2023-08-31 |
1394226 | Unsigned code execution on enrolled devices via modified RMA shim | - | 2023-08-30 |
1435142 | Security: UAF in base::ObserverList<ash::ArcWindowWatcher::ArcWindowDisplayObserver | $1,000 | 2023-08-30 |
1443107 | Security: Race Condition in amdgpu_ttm_tt_get_user_pages | $1,000 | 2023-08-30 |
1444835 | DCHECK failure in !MaybeHasTurbofanCodeBit::decode(state) in feedback-vector.cc | - | 2023-08-30 |
1447344 | v8_wasm_streaming_fuzzer.exe: Use-after-poison in v8::internal::wasm::ValidateSingleFunction | - | 2023-08-30 |
1447396 | sql_built_in_recovery_fuzzer: Crash in sqlite3VdbeMemSetStr | - | 2023-08-30 |
1381375 | Security: UAF in device_del | $5,000 | 2023-08-29 |
1398995 | Security: ChromeOS cryptohome udev rules chgrp argument injection (unexploitable) | - | 2023-08-29 |
1420885 | ServiceWorkers in credentialless iframes could access long lived cookies | $2,000 | 2023-08-29 |
1443100 | Heap-use-after-free in CPDF_StructElement::~CPDF_StructElement | - | 2023-08-29 |
1447392 | Crash in memfd:swiftshader_jit | - | 2023-08-29 |
1447430 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsHeapObject()) in heap- | - | 2023-08-29 |
1398985 | Security: ChromeOS shill-scripts Command Execution | $1,000 | 2023-08-28 |
1403836 | Security: PWA Installation can be unknowingly installed and launched into by pressing the "Enter" button repeatedly | $1,000 | 2023-08-28 |
1407576 | Security: Hostname checking options can all be empty when Default option is toggled "Server CA certificate" in Wi-Fi UI in ChromeOS Flex | $2,000 | 2023-08-28 |
1443956 | Security: Chrome OS cros_camera_service integer overflow in calculate_camera_metadata_size can cause OOB write | $10,000 | 2023-08-28 |
1443961 | Security: Chrome OS cros_camera_service OOB read and write when handling metadata_entry | $7,000 | 2023-08-28 |
1443964 | Security: Chrome OS cros_camera_service OOB write in function CameraDeviceAdapter::RegisterBufferLocked | $7,000 | 2023-08-28 |
1446841 | CHECK failure: static_cast<uintptr_t>(caller_frame_top_) - total_output_frame_size > stack_guar | - | 2023-08-28 |
1446918 | Security: Debug check failed: NodeTypeIs(type, known_info->type) | - | 2023-08-28 |
1447123 | DCHECK failure in NodeTypeIs(known_info->type, merger.node_type()) in maglev-graph-builder.cc | - | 2023-08-28 |
96885 | UXSS via Object::GetRealNamedPropertyInPrototypeChain | $2,337 | 2023-08-28 |
1446738 | Heap-use-after-free in blink::scheduler::MainThreadTaskQueue::ShutdownTaskQueue | - | 2023-08-26 |
1411109 | Security: Android - Bypass the Protection of input fields cache (Autofill) Bypass 1398579 | $3,000 | 2023-08-25 |
1442086 | Security: Chrome OS cras server OOB read & write because of share memory content can be controlled by arcvm and chrome browser | $10,000 | 2023-08-25 |
1445275 | DCHECK failure in NodeTypeIs(type, known_info->type) in maglev-graph-builder.cc | - | 2023-08-25 |
1446221 | v8_wasm_streaming_fuzzer: Use-after-poison in v8::internal::wasm::WasmFullDecoder<v8::internal::wasm::Decoder::FullValidationT | - | 2023-08-25 |
1436018 | Security: Linux kernel (including Chrome OS kernels) msm drm gpu driver refcount leak in msm_ioctl_gem_submit | - | 2023-08-24 |
1407519 | Security: .lnk / .local Restricted Extension Download Bypass | - | 2023-08-23 |
1423656 | Security: heap-use-after-free in extensions::NativeExtensionBindingsSystem::HandleResponse | $1,000 | 2023-08-23 |
1433304 | heap-buffer-overflow in SavedTabGroup | $3,000 | 2023-08-23 |
1443401 | Security: UAF in extensions::WebViewFindHelper::FindReply in browser process | $10,000 | 2023-08-23 |
1443452 | Extending non-extensible objects leads to type confusion in V8 | - | 2023-08-23 |
1443955 | Security:stack-buffer-overflow in vrend_shader_sampler_views_mask_get bypassed | $7,000 | 2023-08-23 |
1444348 | heap-use-after-free : nlp_fst::SortedMatcher<nlp_fst::Fst<nlp_fst::ArcTpl<nlp_fst::TropicalWeightTpl<float>, int, int>>>::GetLabel | - | 2023-08-23 |
1446239 | Abrt in v8::internal::maglev::LoadPolymorphicDoubleField::GenerateCode | - | 2023-08-23 |
1433577 | Security: heap-use-after-free ui/ozone/platform/wayland/host/wayland_connection.cc | $3,000 | 2023-08-22 |
1437137 | DCHECK failure in var.has_value() in optimization-phase.h | - | 2023-08-22 |
1440695 | Security: Type confusion in v8::internal::Object::SetPropertyWithAccessor | - | 2023-08-22 |
1441030 | Security: chrome os vboot_reference vb2_unpack_key_buffer can cause integer overflow on 32 bit binaries | - | 2023-08-22 |
1444195 | heap-use-after-free : TlmProvider::AppendNameToMetadata | - | 2023-08-22 |
1444842 | CHECK failure: (location_) != nullptr in maybe-handles.h | - | 2023-08-22 |
1445426 | Security: Use-after-free in CPWL_ComboBox::OnKeyDown | $9,000 | 2023-08-22 |
1445926 | DCHECK failure in var.has_value() in optimization-phase.h | - | 2023-08-22 |
1368270 | Security: Safe Browsing vs manual Safe Browsing Query in Transparency Report | - | 2023-08-21 |
1434330 | Security: cursor pointer can cover autofill prompt | $1,000 | 2023-08-21 |
1443114 | Memory corruption in v8::internal::MemoryChunk::ReleaseTypedSlotSet | - | 2023-08-21 |
1445228 | DCHECK failure in map().has_prototype_slot() in js-function-inl.h | - | 2023-08-21 |
1445235 | DCHECK failure in 0 == memcmp(reinterpret_cast<void*>(fresh->address() + offset), reinterpret_cast | - | 2023-08-21 |
1445286 | CHECK failure: is_int8(disp) in assembler-x64.cc | - | 2023-08-21 |
1443218 | DCHECK failure in expected_value_stack_size <= stack_value_types_for_debugging_.size() + num_gc_st | - | 2023-08-19 |
1444134 | CHECK failure: maybe_constructor.IsJSFunction() in call-optimization.cc | - | 2023-08-19 |
1444238 | Security: PDFium (XFA) Use-after-free in CPWL_ComboBox::OnChar | $9,000 | 2023-08-19 |
1444360 | Security: UAF in CommitErrorPage | $31,000 | 2023-08-19 |
1444581 | Security: PDFium (XFA) Use-after-free in CFFL_ListBox::SaveData | $9,000 | 2023-08-19 |
1444025 | Heap-use-after-free in v8::internal::TracedHandles::Destroy | $9,000 | 2023-08-17 |
1394410 | Security: Permission Prompts can be made totally hidden and user can Accept and interact with sensitive data without being aware Similar to (1358647) | $2,000 | 2023-08-16 |
1425637 | Security: Race Condition UAF in evdi_gem_create | $11,000 | 2023-08-16 |
1432470 | Security: CSA_DCHECK failed: Torque assert 'IsConstructor(target)' | $10,000 | 2023-08-16 |
1440006 | Security: heap-use-after-free in vrend_set_single_image_view | $5,000 | 2023-08-16 |
1441348 | DCHECK failure in has_prototype_slot(cage_base) in js-function-inl.h | - | 2023-08-16 |
1441804 | Security: wildptr in webrtc::videocapturemodule::GetMaxOfFrameArray | - | 2023-08-16 |
1442516 | Security: UAF in content::BrowserPluginGuest::GetProspectiveOuterDocument() in browser process | $10,000 | 2023-08-16 |
1443080 | Security: Type Confusion in V8 | - | 2023-08-16 |
1443193 | Security DCHECK failure: unit.TextContentEnd() <= text.length() in ng_offset_mapping.cc | - | 2023-08-16 |
1443200 | DCHECK failure in !Bytecodes::IsPrefixScalingBytecode(current_bytecode) in bytecode-array-iterator | - | 2023-08-16 |
1443445 | Security: Stack-based Buffer Overflow in ANGLE source code (CreateTemporaryFile function) | - | 2023-08-16 |
1360710 | Security: Custom cursor can overlay parts of the permission prompt. | $2,000 | 2023-08-15 |
1370705 | Arbitrary URI Origin Spoof on Chrome Android Incognito mode | $1,000 | 2023-08-15 |
1433503 | v8_inspector_fuzzer.exe: Heap-use-after-free in v8_inspector::EvaluateCallback::sendFailure | - | 2023-08-15 |
1435438 | Security: stack-buffer-overflow in vrend_shader_sampler_views_mask_get | $7,000 | 2023-08-15 |
1436013 | Security: out-of-bounds write in tgsi_scan_shader | $7,000 | 2023-08-15 |
1436049 | Security: out-of-bounds access in tgsi_scan_shader | $7,000 | 2023-08-15 |
1438400 | Security: Heap-use-after-free in SearchCompanionSidePanelCoordinator::CreateCompanionEntry | $5,000 | 2023-08-15 |
1440005 | Security: heap-use-after-free in vrend_set_uniform_buffer | $5,000 | 2023-08-15 |
1440653 | Security: heap-use-after-free in vrend_apply_sampler_state | $7,000 | 2023-08-15 |
1441417 | Security:OOB read in vrend_set_single_image_view | $2,000 | 2023-08-15 |
1441241 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsJSReceiver_NonInline(* | - | 2023-08-14 |
1442262 | Crash in Builtins_InterpreterEntryTrampoline | - | 2023-08-14 |
1442301 | DCHECK failure in AllocatedSinceLastGC() + limit() - top() == std::accumulate(begin(), end(), 0, [ | - | 2023-08-14 |
1423634 | GpuMemoryAblationExperiment and Vulkan stack overflow | - | 2023-08-12 |
1429141 | DCHECK failure in type.IsWord32() in assert-types-reducer.h | - | 2023-08-12 |
1421616 | Security: fastfail in Builtins_DeoptimizationEntry_Eager | - | 2023-08-11 |
1436790 | Security: Chrome OS amd drm gpu driver UAF bug in amdgpu_sched_ioctl which can be triggered from chrome browser context | $10,000 | 2023-08-11 |
1431761 | Security: [WebGL/WebGPU] Integer overflow in Swiftshader JIT optimization leads to oob read/write | - | 2023-08-10 |
1437674 | UAF in CrostiniManager::profile_; | - | 2023-08-10 |
1440764 | Security: [swiftshader] heap-use-after-free on vk::Query::start (another) | $10,000 | 2023-08-10 |
1441270 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in marl::Scheduler::Worker::runUntilIdle | - | 2023-08-10 |
1435422 | Security: stack-buffer-overflow in prepare_so_movs | $7,000 | 2023-08-09 |
1440685 | Fatal error in Type cast failed in CAST(args.GetReceiver()) at ../../src/builtins/builtins-call | - | 2023-08-09 |
1442015 | DCHECK failure in source_position_iterator_.code_offset() > offset in maglev-graph-builder.h | - | 2023-08-09 |
1442263 | Security: WebGPU D3D12 Descriptor Heap Issue Could Cause Unauthorized Memory Access | - | 2023-08-09 |
1404039 | [ChromeOS Security] Multiple Share Memory TOCTOU Vulnerabilities in Qualcomm Snapdragon 7c Gen 2 Camera Drivers Which can be triggered from Chome Browser Context | $10,000 | 2023-08-08 |
1425115 | file_path_fuzzer: Global-buffer-overflow in base::FilePath::HFSFastUnicodeCompare | - | 2023-08-08 |
1429059 | Fatal error in SimplifiedLoweringVerifierError: verified type Boolean of node #NUMBER:TypeGuard | - | 2023-08-08 |
1434669 | Security: UAF in ReadAnythingAppController::OnAXTreeDistilled | $7,000 | 2023-08-08 |
1435166 | Security: UAF in DevToolsDataSource::OnLoadComplete | $3,000 | 2023-08-08 |
1436863 | Security: heap-use-after-free in translate_tex | $7,000 | 2023-08-08 |
1440893 | DCHECK failure in HasValue() in maglev-graph-builder.h | - | 2023-08-08 |
1441262 | Crash in v8::internal::maglev::MaglevGraphBuilder::TryFindNextBranch | - | 2023-08-08 |
1400905 | Security: UAF in AutofillSnackbarControllerImpl::OnActionClicked | $7,000 | 2023-08-07 |
1441089 | DCHECK failure in source_position_iterator_.code_offset() > offset in maglev-graph-builder.h | - | 2023-08-05 |
1441092 | DCHECK failure in index >= 0 in bytecode-liveness-map.h | - | 2023-08-05 |
1405223 | Chrome Theme contains link to malware, safe browser does not catch it | $1,000 | 2023-08-04 |
1426807 | Security: Extensions with "download" permissions can read local files by using FSA API | $2,000 | 2023-08-03 |
1430089 | Security: UAF in sampler_state | $10,000 | 2023-08-03 |
1433211 | Security: Internal JavaScript object access via Origin Trials | - | 2023-08-03 |
1433468 | Security:stack buffer overflow in set_stream_out_varyings | $7,000 | 2023-08-03 |
1433506 | Security: heap-use-after-free in vrend_draw_bind_abo_shader | $7,000 | 2023-08-03 |
1434231 | Security:heap-buffer-overflow in rewrite_1d_image_coordinate | $2,000 | 2023-08-03 |
1436050 | Portals URL spoof after crash | $2,000 | 2023-08-03 |
1439691 | DCHECK failure in Smi::IsValid(value) in smi.h | - | 2023-08-03 |
1439781 | CHECK failure: (location_) != nullptr in maybe-handles.h | - | 2023-08-03 |
1440164 | DCHECK failure in !has_optimized_code() || optimized_code().marked_for_deoptimization() || (CodeKi | - | 2023-08-03 |
1440463 | Vulnerability reported in /third_party/harfbuzz-ng | - | 2023-08-03 |
1440490 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsJSObject_NonInline(*th | - | 2023-08-03 |
1440714 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in marl::Scheduler::Worker::runUntilIdle | - | 2023-08-03 |
1428820 | heap-use-after-free : net::SpdyProxyClientSocket::RunWriteCallback | - | 2023-08-02 |
1433180 | Security: use-after-poison libANGLE\renderer\d3d\d3d11\VertexBuffer11.cpp:129 in rx::VertexBuffer11::storeVertexAttributes | $11,000 | 2023-08-02 |
1434904 | Debug check failed: IsSweepingInProgress() in ../../src/heap/gc-tracer.cc, line 584 | - | 2023-08-02 |
1439688 | Heap-use-after-free in blink::PaintArtifactCompositor::CollectPendingLayers | - | 2023-08-02 |
1381455 | Use-after-free in the filepicker | $1,000 | 2023-08-01 |
1426480 | Failed DCHECK on page finalization in ExternalCanvasResource::~ExternalCanvasResource | - | 2023-08-01 |
1427918 | Security:UAF in content::SyntheticPointerAction::ForwardTouchOrMouseInputEvents(browser process) | $3,000 | 2023-08-01 |
1430985 | Security: WebGPU zero length GPUBuffers return address `0xCAFED00D` | - | 2023-08-01 |
1433460 | Security: Chrome OS i915 drm gpu driver create_clone UAF | $10,000 | 2023-08-01 |
1433646 | Security: arbitrary address write in allocate_temp_range | $7,000 | 2023-08-01 |
1437346 | DCHECK failure in static_cast<unsigned>(length_) > static_cast<unsigned>(i) in zone-list.h | - | 2023-08-01 |
1439211 | Fatal error in Type cast failed in CAST(LoadRegisterAtOperandIndex(0)) at ../../src/interpreter | - | 2023-08-01 |
1439694 | DCHECK failure in !Heap::InYoungGeneration(table) in ephemeron-remembered-set.cc | - | 2023-08-01 |
1439699 | DCHECK failure in last_position.IsKnown() in profiler-listener.cc | - | 2023-08-01 |
1427804 | Security: UAF in extensions::SupervisedUserExtensionsDelegateImpl::ShowParentPermissionDialogForExtension | $4,000 | 2023-07-31 |
1432892 | Security:heap-buffer-overflow in translate | $1,000 | 2023-07-31 |
1435080 | dawn_wire_server_and_vulkan_backend_fuzzer.exe: Crash in CmdBeginRenderPass::execute | - | 2023-07-31 |
1432249 | Crash in memfd:swiftshader_jit | - | 2023-07-30 |
1434955 | DCHECK failure in HasOutputRegister(target) in maglev-graph-builder.h | - | 2023-07-29 |
1435078 | Crash in unsigned int v8::base::AsAtomicImpl<int>::Relaxed_Load<unsigned int> | - | 2023-07-29 |
1435079 | DCHECK failure in isolate->context().is_null() || isolate->context().IsContext() in runtime-intern | - | 2023-07-29 |
1435152 | CHECK failure: shared(isolate).IsSharedFunctionInfo() | - | 2023-07-29 |
1435756 | CHECK failure: function__value.IsJSFunction() | - | 2023-07-29 |
1423360 | heap-use-after-free : base::internal::begin | - | 2023-07-28 |
1430323 | Security: UAF in vrend_update_stencil_state | $7,000 | 2023-07-28 |
1434531 | DCHECK failure in current_counter_ < aoc.next_counter_ in allocation-observer.cc | - | 2023-07-28 |
1435077 | CHECK failure: function__value.IsJSFunction() | - | 2023-07-28 |
1430381 | Security: UAF in vrend_renderer_pipe_resource_set_type | $7,000 | 2023-07-27 |
1432508 | net_host_resolver_manager_fuzzer.exe: Heap-use-after-free in base::sequence_manager::internal::ThreadControllerWithMessagePumpImpl::DoWorkImp | - | 2023-07-27 |
1398986 | Security: ChromeOS kerberosd-exec command execution | $2,000 | 2023-07-26 |
1427353 | Security: Error Path Double Free in __i915_gem_ttm_object_init | $1,000 | 2023-07-26 |
1422844 | oob in operator_selection | - | 2023-07-25 |
1425370 | Security: UAF in MLGraphXnnpack::BuildOnBackgroundThread | $11,000 | 2023-07-25 |
1425922 | Security: UAF in blink::MLGraphXnnpack::ComputeOnBackgroundThread | $8,000 | 2023-07-25 |
1432603 | Security: [0-day] Integer overflow in SkSLVMCodeGenerator (skia) | - | 2023-07-25 |
1434193 | DCHECK failure in 0 == result in mutex.cc | - | 2023-07-25 |
1428786 | memory corruption in v8 | $7,000 | 2023-07-24 |
1419895 | Use-of-uninitialized-value in v8::internal::StackFrameIteratorForProfiler::IsValidCaller | - | 2023-07-22 |
1433037 | Crash in Builtins_GeneratorPrototypeNext | - | 2023-07-22 |
1433328 | Vulnerability reported in /third_party/libxslt | - | 2023-07-22 |
1068358 | mount-encrypted: creating incorrect encstateful space in dev mode can force dumping encstateful key to disk | - | 2023-07-21 |
1414398 | Security: Bypass Issue 1385343 Extension with <all_urls> permission can read arbitrary local files although (Allow access to file URLs) is disabled | $5,000 | 2023-07-21 |
1426521 | Security: Heap-use-after-free in ExclusiveAccessBubbleViews::UpdateBounds | $10,000 | 2023-07-21 |
1427012 | Security: Race Condition UAF in l2cap_disconnect_req and l2cap_disconnect_rsp | $5,000 | 2023-07-21 |
1430079 | Security: heap-use-after-free on ash/drag_drop/tab_drag_drop_windows_hider.cc | $3,000 | 2023-07-21 |
1430269 | Security: Very long extension name spoofs debugging infobar and breaks other UI | $500 | 2023-07-21 |
1430692 | Security: UAF in Chrome OS Camera App ash::CameraAppHelperImpl::OnStorageStatusUpdated | $5,000 | 2023-07-21 |
1413813 | Fenced frame spoof documentPictureInPicture | $4,000 | 2023-07-20 |
1430981 | DCHECK failure in static_cast<unsigned>(index) < static_cast<unsigned>(length()) in fixed-array-in | - | 2023-07-20 |
1431729 | __mm256_castsi128_si256 high-bit uninitialized memory eventually leads to unknown behavior(such as b | - | 2023-07-20 |
1407048 | Security: Race Condition UAF in amdtee_open_session | $10,000 | 2023-07-19 |
1424177 | LAN9500, LAN75xx driver information leak | $3,000 | 2023-07-19 |
1427332 | oob write in vrend_renderer_transfer_write_iov | $15,000 | 2023-07-19 |
1428743 | Extension has access to chrome://new-tab-page | - | 2023-07-19 |
1430106 | Security: heap-use-after-free on chrome/browser/ui/ash/crosapi_new_window_delegate.cc | $3,000 | 2023-07-19 |
1431659 | CHECK failure: ReadOnlyHeap::Contains(heap_object) || shared_space_->Contains(heap_object) || s | - | 2023-07-19 |
1431834 | Use-after-poison in mojo::SimpleWatcher::OnHandleReady | - | 2023-07-19 |
1432210 | Security: [0-day] JIT optimisation issue | - | 2023-07-19 |
1432248 | DCHECK failure in !value->properties().is_conversion() in maglev-interpreter-frame-state.h | - | 2023-07-19 |
1416350 | Security: Document PiP can spoof top-level page origin, show attacker content in PiP window, open PiP windows from iframes | $4,000 | 2023-07-18 |
1422250 | Security: Race Condition UAF in evdi_painter_mode_changed_notify | $6,000 | 2023-07-18 |
1429372 | freetype_cff_ftengine_fuzzer: Heap-buffer-overflow in tt_size_reset_iterator | - | 2023-07-18 |
1429753 | DCHECK failure in source_position_iterator_.code_offset() > offset in maglev-graph-builder.h | - | 2023-07-18 |
1430649 | Stack-use-after-scope in blink::AnimationFrameTimingMonitor::Did | - | 2023-07-18 |
1432198 | GPU failure in base::sequence_manager::internal::ThreadControllerWithMessagePumpImpl::DoWork | - | 2023-07-18 |
1431635 | DCHECK failure in value.InAnySharedSpace() in marking-barrier-inl.h | - | 2023-07-17 |
1431773 | Use-after-poison in mojo::InterfaceEndpointClient::HandleValidatedMessage | - | 2023-07-17 |
1430644 | Security: heap-buffer-overflow on WebSQL sqlite3VdbeSorterInit | $1,000 | 2023-07-14 |
1414235 | heap-buffer-overflow : charntorune | - | 2023-07-13 |
1425779 | Security: SEGV_ACCERR in v8 JSArrayBuffer::Attach | - | 2023-07-13 |
1429201 | Security: Memory corruption due to HeapVector iterator invalidation | $8,000 | 2023-07-13 |
1429570 | CHECK failure: (chunk->slot_set<OLD_TO_NEW>()) == nullptr in heap-verifier.cc | - | 2023-07-13 |
1429787 | CHECK failure: ReadOnlyHeap::Contains(heap_object) || shared_space_->Contains(heap_object) || s | - | 2023-07-13 |
1430221 | Security: [WEBGPU] UAF in SetForwardingDeviceCallbacks | - | 2023-07-13 |
1430927 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts.value() || (IsHeapObject()) in heap- | - | 2023-07-13 |
1038996 | MessageSender.url should not be spoofable by a compromised renderer | - | 2023-07-12 |
1420161 | Security: RACE CONDITION UAF in kfd_ioctl_unmap_memory_from_gpu | $11,000 | 2023-07-12 |
1427845 | DCHECK failure in HasFeedbackMetadata() in shared-function-info-inl.h | - | 2023-07-12 |
1428853 | lightweight-heap-use-after-free : profile_metrics::GetBrowserProfileType | - | 2023-07-12 |
1415129 | Security: Uninitialized Pointer in `msm_parse_post_deps` | $16,000 | 2023-07-11 |
1429720 | Security: Mojo message validation bypass due to shared memory. | - | 2023-07-11 |
1429197 | Security: Memory corruption due to accessing invalid context | $8,000 | 2023-07-10 |
1429810 | DCHECK failure in new_properties.can_eager_deopt() implies properties().can_eager_deopt() in magle | - | 2023-07-10 |
1406900 | Security: FedCM should have clickjacking protection | $1,000 | 2023-07-08 |
1408120 | heap overflow in ForeignSessionHandler::OpenForeignSessionWindows | $3,000 | 2023-07-08 |
1429323 | DCHECK failure in ValidOpInputRep(graph, input, rep) in operations.h | - | 2023-07-07 |
1429464 | DCHECK failure in use_reprs - UseRepresentationSet({UseRepresentation::kInt32, UseRepresentation:: | - | 2023-07-07 |
1367125 | Security: [webkit] heap-use-after-free in WebCore::DOMWrapperWorld::~DOMWrapperWorld()+0x25b | $7,000 | 2023-07-06 |
1410191 | Crash in vk::ImageView::clear | $15,000 | 2023-07-06 |
1417881 | sql_recovery_fuzzer: Use-of-uninitialized-value in sql::recover::LeafPayloadReader::PopulateNextOverflowPageId | - | 2023-07-06 |
1423304 | Security: Permission bypass due to not erase request properly | $7,500 | 2023-07-06 |
1424337 | UAF in DevToolsAgentHostImpl::ForceDetachAllSessions(with headless mode and puppeteer) | $3,000 | 2023-07-06 |
1427431 | Chrome Crashpad arbitrary file create | $3,000 | 2023-07-06 |
1427449 | UAF in content::NavigationState::RunCommitSameDocumentNavigationCallback | $7,000 | 2023-07-06 |
1428984 | neteq_signal_fuzzer: Heap-use-after-free in webrtc::test::FuzzSignalInput::PopPacket | - | 2023-07-06 |
900441 | Security: Content-Type & Nosniff Ignored in Chrome for iOS | $500 | 2023-07-05 |
1426851 | Chrome: Crash Report - permissions::PermissionRequestManager::PreIgnoreQuietPromptInternal | - | 2023-07-05 |
1427746 | Security: Triggering SEGV && Debug check failed: reinterpret_cast<Address>(result) < reinterpret_cast<Address>(data->limit) in v8 | - | 2023-07-05 |
1427865 | Arbitrary OOB read and write with WebGL via SwiftShader | $10,000 | 2023-07-05 |
1427876 | Security: Debug check failed: last_position.IsKnown(). | - | 2023-07-05 |
1428440 | Security: Heap-use-after-free in ScreenAIService::TriggerProcessingNextTaskInQueue | $11,000 | 2023-07-05 |
1428524 | DCHECK failure in input_phi->value_representation() == repr in maglev-phi-representation-selector. | - | 2023-07-05 |
1428580 | DCHECK failure in has_value() in heap-refs.h | - | 2023-07-05 |
1425058 | Security: UAF in base::ObserverList<ash::eche_app::EcheConnectionStatusObserver::Observer | $1,000 | 2023-07-04 |
1426351 | Security: Heap-use-after-free in ProfileTokenNavigationThrottle::WillProcessRespons | $4,000 | 2023-07-04 |
1427043 | Heap-use-after-free in SavedTabGroupBar | $3,000 | 2023-07-04 |
1427388 | Segv on unknown address in unsigned int v8::base::AsAtomicImpl<int>::Relaxed_Load<unsigned int> | - | 2023-07-04 |
1427882 | 3 vulnerabilities reported in /third_party/libxml | - | 2023-07-04 |
1428354 | DCHECK failure in scope->is_declaration_scope() implies !scope->AsDeclarationScope()->was_lazily_p | - | 2023-07-04 |
1428357 | skia_path_fuzzer: Crash in SkMallocPixelRef::MakeAllocate | - | 2023-07-04 |
1428584 | DCHECK failure in !HAS_WEAK_HEAP_OBJECT_TAG(ptr_) in tagged-impl-inl.h | - | 2023-07-04 |
1425821 | Security:Kernel Info Leak in cros_ec_chardev_ioctl_xcmd | $4,000 | 2023-07-03 |
1427719 | net_http_server_fuzzer: Heap-use-after-free in net::HttpServer::HandleReadResult | - | 2023-07-03 |
1427943 | DCHECK failure in ThreadId::Current() == thread_id() in isolate.cc | - | 2023-07-03 |
1337597 | dawn_wire_server_and_vulkan_backend_fuzzer: Segv on unknown address in __tls_get_addr | - | 2023-06-30 |
1350561 | Security: heap-use-after-free ui/events/event_processor.cc:77:26 in ui::EventProcessor::OnEventFromSource(ui::Event*) | $4,000 | 2023-06-30 |
1398991 | Security: ChromeOS pluginvm arbitrary chmod 777 | $5,000 | 2023-06-30 |
1425769 | Security: segv in JsonStringifier::SerializeString | $8,000 | 2023-06-30 |
1426157 | DCHECK failure in last_position.IsKnown() in profiler-listener.cc | - | 2023-06-30 |
1413031 | Security: Race Condition UAF in hci_cmd_sync_work | $8,500 | 2023-06-28 |
1416380 | Security: Document PiP window can be resized and moved by compromised renderer, user can interact with sensitive UI using keyboard without being aware | $1,000 | 2023-06-28 |
1420029 | DCHECK failure in type.IsWord32() in assert-types-reducer.h | - | 2023-06-28 |
1420510 | Security: heap-use-after-free in blink::WebString::WebString | $3,000 | 2023-06-28 |
1411593 | Global-buffer-overflow in gl::GLDisplayManager<gl::GLDisplayEGL>::RemoveGpuPreference | - | 2023-06-27 |
1413586 | Security: Android permission prompt tapjacking | $2,000 | 2023-06-27 |
1418224 | Security: String with different encoding mismatch, leading Out-of-bounds access. | $5,000 | 2023-06-27 |
1420631 | Security: ChromeOS cras D-Bus cras_iodev_start_volume_ramp memory corruption | $3,000 | 2023-06-27 |
1424955 | Security: Debug check failed: IsSweepingInProgress() | $8,000 | 2023-06-27 |
1425339 | Security: Heap-use-after-free in LocalTabGroupListener::AddWebContents | $5,000 | 2023-06-27 |
1425630 | Heap-use-after-free in blink::NGGridLayoutAlgorithm::BuildGridSizingSubtree | - | 2023-06-27 |
1425670 | Heap-use-after-free in blink::NGSubgriddedItemData::CreateSubgridCollection | - | 2023-06-27 |
1305410 | Security: crosvm user command execution | - | 2023-06-26 |
1361042 | Security: Lockscreen - phone options available | $1,000 | 2023-06-26 |
1413701 | Security: UAF in void perfetto::DataSource<perfetto::perfetto_track_event::TrackEvent | $3,000 | 2023-06-26 |
1424486 | Crash in Builtins_KeyedHasIC | - | 2023-06-26 |
1425333 | Security: unreachable code at src/builtins/torque-internal.tq:101:45 | - | 2023-06-26 |
1425488 | Security: SEGV_MAPERR 00001bd0c4a9 in V8 | - | 2023-06-26 |
1425765 | DCHECK failure in !HAS_WEAK_HEAP_OBJECT_TAG(ptr_) in tagged-impl-inl.h | - | 2023-06-26 |
1425782 | Crash in Builtins_SortCompareUserFn | - | 2023-06-26 |
1425338 | Security: Heap-use-after-free in SavedTabGroupButton::DeleteGroupPressed | - | 2023-06-24 |
1290664 | Security: Autofill prompt can be obscured by Picture-in-Picture overlay, allows stealthy autofill data theft | $5,000 | 2023-06-23 |
1415330 | Security: TALOS-2023-1724 - Google Chrome WebGL rx::Image11::disassociateStorage use-after-free vulnerability | $15,000 | 2023-06-23 |
1421619 | Security: Check failed: frame_index < output_count_ - 1. | - | 2023-06-23 |
1422533 | Heap-use-after-free in blink::NGTextDecorationPainter::UpdateDecorationInfo | $11,000 | 2023-06-23 |
1422876 | UAF in PerformanceControlsHatsService | - | 2023-06-23 |
1423610 | Security: SEGV_ACCERR in v8 | $21,000 | 2023-06-23 |
1424721 | DCHECK failure in isolate->main_thread_local_heap()->IsRunning() in handles-inl.h | - | 2023-06-23 |
1424926 | DCHECK failure in CpuFeatures::IsSupported(*feature) in macro-assembler-shared-ia32-x64.h | - | 2023-06-23 |
1424995 | Security: Heap-use-after-free in TabGroupModel::GetTabGroup | $3,000 | 2023-06-23 |
1425124 | Fatal error in Type representation error: node Phi (input @1 = Identity) type Tagged is not Int | - | 2023-06-23 |
1375133 | Security: Device chooser dialogs do not show origin if initiator origin is opaque | $3,000 | 2023-06-21 |
1407564 | Security: Race Condition UAF in hidp_session_thread | $20,000 | 2023-06-21 |
1418549 | Security: Document PIP inherits wrong origin when opened from an extension popup | $2,000 | 2023-06-21 |
1419732 | Bypass 1349146, local file access checks can be bypassed by using `file:` instead of `file://` | $5,000 | 2023-06-21 |
1421609 | Security: Debug check failed: !IsBound() || (Predecessors().size() == 1 && kind_ == Kind::kLoopHeader) | - | 2023-06-21 |
1422830 | UAF in v8_inspector | $1,000 | 2023-06-21 |
1422836 | Security: use-after-poison animation_frame_timing_monitor.cc:173 in blink::AnimationFrameTimingMonitor::OnMicrotasksCompleted | - | 2023-06-21 |
1423207 | Security: Security: SEGV_MAPERR 00000000d849 in v8 | - | 2023-06-21 |
1423258 | Security: Bypass https://chromium-review.googlesource.com/c/chromium/src/+/4294941 using upper-cased file: protocol (Source maps support for file:// URLs gives devtools_page extensions local file access) | $5,000 | 2023-06-21 |
1423580 | DCHECK failure in input_index == StoreTaggedFieldWithWriteBarrier::kObjectIndex implies phi->value | - | 2023-06-21 |
1424187 | Check permissions of shared memory for Linux lock | - | 2023-06-21 |
1424274 | Use-of-uninitialized-value in v8::internal::Sweeper::LocalSweeper::ParallelIteratePromotedPageForRememberedSet | - | 2023-06-21 |
1424276 | Use-of-uninitialized-value in v8::internal::Sweeper::LocalSweeper::ParallelIteratePromotedPageForRememberedSet | - | 2023-06-21 |
1424307 | Crash in Builtins_RecordWriteIgnoreFP | - | 2023-06-21 |
1424487 | DCHECK failure in UsableCapacity() <= TotalCapacity() in new-spaces.cc | - | 2023-06-21 |
1418061 | Security: Chrome on Android can self-intent into CCT, allowing sandboxed iframe allow-popups-to-escape-sandbox bypass. | $1,000 | 2023-06-19 |
1421268 | Security: Lack of validation in mojom traits for media::mojom::VideoFrame. | - | 2023-06-19 |
1423139 | DCHECK failure in IsPrimitiveMap() in map-inl.h | - | 2023-06-19 |
1411862 | heap-use-after-free in Read Anything | $1,000 | 2023-06-17 |
1422594 | Security: GL_ShaderBinary exposed to untrusted processes. | - | 2023-06-17 |
1422812 | DCHECK failure in string.IsFlat() in string-inl.h | - | 2023-06-17 |
1423402 | DCHECK failure in BasicBlock::GetCommonDominator(block, user_block) == block in effect-control-lin | - | 2023-06-17 |
1417325 | Security: Safe Browsing bypass via data URI, no warning if SB fails | $3,000 | 2023-06-16 |
1418955 | Security: PDFium leaks JSGlobalObject | - | 2023-06-16 |
1419751 | [wasm][memory64][simd] DCHECK failure in is_gp_pair() in liftoff-register.h | - | 2023-06-16 |
1421773 | Security: use-after-free in ManagePasswordsUIController::OnChooseCredentials | $10,000 | 2023-06-16 |
1398990 | Security: ChromeOS Arbitrary Root File Delete | $5,000 | 2023-06-15 |
1411997 | Security: Race Condition UAF in i915_gem_execbuffer2_ioctl | $21,000 | 2023-06-15 |
1413919 | documentPictureInPicture UI spoof via opener | $1,000 | 2023-06-15 |
1422110 | Security DCHECK failed: IsA<Derived>(from) blink::TimelineOffset::Create timeline_offset.cc:82 | $8,000 | 2023-06-15 |
1223346 | Security: heap-use-after-free CmdDrawBase::draw | - | 2023-06-14 |
1374224 | Disallow apps to prevent the lock key | - | 2023-06-14 |
1385714 | Security: Permissions Prompt UI spoof through a custom CSS cursor | $3,000 | 2023-06-14 |
1419831 | Security: PDFium UAF vulns | $7,000 | 2023-06-14 |
1420329 | Security: Heap-buffer-overflowREAD {*} in strtol in freetype library | - | 2023-06-14 |
1421237 | DCHECK failure in object->FitsRepresentation(representation) in objects.cc | - | 2023-06-14 |
1422256 | Crash in Builtins_ObjectPrototypeIsPrototypeOf | - | 2023-06-14 |
1422510 | Crash in v8::internal::HandleBase::IsDereferenceAllowed | - | 2023-06-14 |
1422564 | Crash in v8::internal::Object::AddDataProperty | - | 2023-06-14 |
1422569 | Crash in Builtins_Construct | - | 2023-06-14 |
1421170 | Security: [WebGPU] UAF in TransitionMappableBuffersEagerly | - | 2023-06-13 |
1421257 | DCHECK failure in !IsNullValue(args[1]) && !IsUndefinedValue(args[1]) in maglev-graph-builder.cc | - | 2023-06-13 |
1421451 | Crash in Builtins_StoreTypedElementJSAny_Int16Elements_0 | $9,000 | 2023-06-13 |
1421591 | DCHECK failure in IrOpcode::kInt64Constant == node->opcode() in instruction-selector-x64.cc | - | 2023-06-13 |
1421712 | DCHECK failure in double_registers_.free() | node->double_temporaries() == double_registers_.free( | - | 2023-06-13 |
1365884 | Security: Crostini apps can draw over "Press [Esc] to exit full screen" UI | - | 2023-06-12 |
1420475 | Security: IsA<Derived>(from) blink::LayoutMultiColumnFlowThread::UpdateGeometry layout_multi_column_flow_thread.cc:1684 | - | 2023-06-12 |
1420790 | Security: ChromeOS cras D-Bus audio_thread_config_global_remix memory corruption | $17,500 | 2023-06-12 |
1418561 | Security: heap-use-after-free worker_thread.cc:671 in blink::WorkerThread::InitializeOnWorkerThread | $8,000 | 2023-06-10 |
1421146 | GPU failure in ChromeContentUtilityClient::UtilityThreadStarted | - | 2023-06-10 |
1421152 | GPU failure in content::IntentionallyCrashBrowserForUnusableGpuProcess | - | 2023-06-10 |
1204438 | Security: seneschal shared paths can include symlinks | - | 2023-06-09 |
1406120 | Security: Android Text Selection Menu Able to Overlap Fullscreen Notification Toast | $2,000 | 2023-06-09 |
1407475 | Security: unreachable code in maglev::MaglevGraphBuilder::VisitStaCurrentContextSlot | $7,000 | 2023-06-09 |
1418837 | Security: After refactor, page can use EyeDropper API to bypass mouse movement/keyboard input requirements for autofill (regression of issue 1287364) | $3,000 | 2023-06-09 |
1419718 | Security: web HID memory corruption bug | $8,000 | 2023-06-09 |
1419742 | Crash in blink::AXObjectCacheImpl::RemoveSubtree | - | 2023-06-09 |
1419773 | Security: Heap-use-after-free in UserNotesPageHandler::GetNoteOverviews | $4,000 | 2023-06-09 |
1420107 | Security: Double-free in libwebp WebPEncode (with alpha) under OOM condition | $1,337 | 2023-06-09 |
1420206 | Security: heap-use-after-free fake_video_capture_device.cc:515:15 in media::FakePhotoDevice::TakePhoto | - | 2023-06-09 |
1420719 | Negative-size-param in void v8::internal::WriteFixedArrayToFlat<unsigned char> | - | 2023-06-09 |
1420860 | Crash in v8::internal::JSArray::ArrayJoinConcatToSequentialString | - | 2023-06-09 |
1420863 | Heap-use-after-free in BookmarkBubbleView::BookmarkBubbleDelegate::ShowEditor | - | 2023-06-09 |
1420963 | DCHECK failure in Heap::InToPage(heap_object) in mark-compact.cc | - | 2023-06-09 |
1156246 | Security: tamachiyomi unowned | - | 2023-06-07 |
1278708 | AddressSanitizer: heap-use-after-free in blink::NetworkStateNotifier::NotifyObserversOnTaskRunner | $2,000 | 2023-06-07 |
1404745 | heap-use-after-free : keyboard::decoder::runtime5::GetUnicodesNearShift | - | 2023-06-07 |
1417514 | Security DCHECK failed: !NeedsLayout() || ChildLayoutBlockedByDisplayLock() in layout_object.h | - | 2023-06-07 |
1420117 | Security: SEGV_ACCERR in v8 | - | 2023-06-07 |
1374518 | Security: Presentation API dialog does not show origin if initiator origin is opaque (due to fix for issue 1342072) | $3,000 | 2023-06-06 |
1378476 | Out of bound write in GPU | $15,000 | 2023-06-06 |
1399862 | Insufficient fix for Cross-Origin (Partial) Status Code leak (XS-Leak) | $1,000 | 2023-06-06 |
1410850 | Apps and websites can arbitrarily open new browser windows on Android | - | 2023-06-06 |
1414018 | Security: Heap-buffer-overflow in FrameSinkManagerImpl::UnregisterFrameSinkHierarchy | $5,000 | 2023-06-06 |
1029296 | CrOS: Vulnerability reported in sys-libs/ncurses | - | 2023-06-05 |
1043332 | CrOS: Vulnerability reported in media-sound/sox | - | 2023-06-05 |
1405410 | CrOS: Vulnerability reported in net-misc/curl | - | 2023-06-05 |
1417133 | Security: UAF when code runs after NavigationThrottle's Resume() or CancelDeferredNavigation() are called | $10,000 | 2023-06-05 |
1417176 | Security: Security DCHECK failed: IsA<Derived>(from) blink::StylePropertyMap::append style_property_map.cc:384 | $7,000 | 2023-06-05 |
1417649 | Security: UAF in simple_devtools_protocol_client::SimpleDevToolsProtocolClient::DispatchProtocolMessageTask( | $4,000 | 2023-06-05 |
1418734 | Convert it != .end() DCHECKs for known failures in the wild | - | 2023-06-05 |
1419677 | DCHECK failure in object.Size() == current_.size in invalidated-slots-inl.h | - | 2023-06-05 |
1418223 | pdf_formcalc_context_fuzzer: Segv on unknown address in Builtins_InterpreterPushArgsThenCall | - | 2023-06-04 |
1418706 | v8_wasm_code_fuzzer: DCHECK failure in opcode >> 8 == kGCPrefix in function-body-decoder-impl.h | - | 2023-06-03 |
1412658 | Security: stack-buffer-overflow in crashpad | $3,000 | 2023-06-02 |
1418078 | Vulnerability reported in /third_party/libxml | - | 2023-06-02 |
1418508 | blink_storage_key_fuzzer: Trap in NotImplemented | - | 2023-06-02 |
1418621 | DCHECK failure in !HAS_WEAK_HEAP_OBJECT_TAG(ptr_) in tagged-impl-inl.h | - | 2023-06-02 |
1285604 | Side-channel attack can deanonymize users (potential risk to journalists and activists) "Targeted Deanonymization via the Cache Side Channel: Attacks and Defenses" | - | 2023-06-01 |
1404279 | DCHECK failure in code == topmost_ implies safe_to_deopt_ in deoptimizer.cc | - | 2023-05-31 |
1414278 | UAF in aura::Window | $1,000 | 2023-05-31 |
1414581 | Security: Heap-use-after-free in ash::WizardController::HandleAccelerator | $1,000 | 2023-05-31 |
1414975 | Security: Document PIP origin spoof | $3,000 | 2023-05-31 |
1415008 | Security: Possible UAF in PinManager::NotifyDelete | $1,000 | 2023-05-31 |
1417122 | Security: UAF in PlatformAuthNavigationThrottle::FetchHeadersCallback | $38,000 | 2023-05-31 |
1417185 | Security: heap-buffer-overflow in base::SampleVectorBase::MoveSingleSampleToCounts | - | 2023-05-31 |
1417389 | [Security] V8 Debug check failed: OFFSET_OF(Isolate, string_stream_current_security_token_) == strin | $7,000 | 2023-05-31 |
1412487 | Security: Type confusion in v8 value serializer | $10,000 | 2023-05-30 |
1413539 | Heap-use-after-free in ui::Layer::OnDeviceScaleFactorChanged | - | 2023-05-30 |
1414224 | heap-use-after-free : TemplateURLService::CreateSyncDataFromTemplateURL | - | 2023-05-30 |
1415328 | Security: heap-buffer-overflow in base::debug::ActivityUserData::ActivityUserData | - | 2023-05-30 |
1416785 | base_activity_analyzer_fuzzer: Heap-buffer-overflow in base::debug::ThreadActivityTracker::IsValid | - | 2023-05-30 |
1416921 | base_activity_analyzer_fuzzer: Use-of-uninitialized-value in base::debug::GlobalActivityAnalyzer::PrepareAllAnalyzers | - | 2023-05-30 |
1417089 | Security: Heap-use-after-free in PasswordAutofillManager::DidAcceptSuggestion | $42,000 | 2023-05-30 |
1417353 | Security: Debug check failed: 0 != new_nodes_.count(value) (0 vs. 0). | - | 2023-05-30 |
1417380 | DCHECK failure in CpuFeatures::IsSupported(*feature) in macro-assembler-shared-ia32-x64.h | - | 2023-05-30 |
1417412 | DCHECK failure in 0 != new_nodes_.count(value) in maglev-graph-builder.h | - | 2023-05-30 |
1417463 | DCHECK failure in ValidOpInputRep(graph, left(), input_rep) in operations.h | - | 2023-05-30 |
1417585 | Map deprecation racing with concurrent compilation can break invariant | - | 2023-05-30 |
1417908 | v8_wasm_fuzzer: Global-buffer-overflow in v8::internal::wasm::WasmFullDecoder<v8::internal::wasm::Decoder::NoValidationTag | - | 2023-05-30 |
1415366 | UAF in permissions::PermissionRequest::request_type | $41,000 | 2023-05-29 |
1381812 | sql_recovery_fuzzer: Use-of-uninitialized-value in sql::recover::LeafPayloadReader::ReadPayload | - | 2023-05-28 |
1415371 | crashpad_process_snapshot_intermediate_dump_fuzzer: Heap-buffer-overflow in crashpad::internal::ExceptionSnapshotIOSIntermediateDump::InitializeFromMachExce | - | 2023-05-28 |
1416828 | Heap-use-after-free in ui::Layer::OnDeviceScaleFactorChanged | - | 2023-05-28 |
1411210 | Security: [swiftshader] heap-use-after-free on vk::Query::start | $15,000 | 2023-05-27 |
1417317 | heap-buffer-overflow in base::PersistentHistogramAllocator::GetHistogram | - | 2023-05-27 |
1417370 | Use-after-poison in v8::internal::maglev::MaxCallDepthProcessor::ConservativeFrameSize | - | 2023-05-27 |
1417386 | DCHECK failure in new_properties.can_eager_deopt() implies properties().can_eager_deopt() in magle | - | 2023-05-27 |
1341430 | Security: Page can obtain autofill data with two consecutive taps with minimal user awareness, bypasses issue 1240472 and issue 1279268 fixes | $3,000 | 2023-05-26 |
1394736 | Security:UAF in content::SyntheticMouseDriver::DispatchEvent(browser process) | $2,000 | 2023-05-26 |
1402533 | heap-use-after-free : base::ScopedObservation<ash::WindowState, ash::WindowStateObserver>::Reset | - | 2023-05-26 |
1412343 | v8 oob read in turboshaft::Graph::IncrementInputUses | $7,000 | 2023-05-26 |
1413628 | Security: use-after-poison rtp_contributing_source_cache.cc:215 in blink::RtpContributingSourceCache::ClearCache | $4,000 | 2023-05-26 |
1414146 | DCHECK failure in !detail::is_float_special_value(min) in types.h | - | 2023-05-26 |
1414201 | DCHECK failure in IsFloat64() in types.h | - | 2023-05-26 |
1414255 | DCHECK failure in min <= max in type-inference-reducer.h | - | 2023-05-26 |
1415158 | flac_audio_handler_fuzzer: Heap-buffer-overflow in media::FlacAudioHandler::WriteCallbackInternal | - | 2023-05-26 |
1415249 | DCHECK failure in !receiver->IsAccessCheckNeeded() || lookup->name()->IsPrivate() in ic.cc | - | 2023-05-26 |
1416146 | flac_audio_handler_fuzzer: Trap in std::Cr::__libcpp_verbose_abort | - | 2023-05-26 |
1416695 | DCHECK failure in !detail::is_float_special_value(max) in types.h | - | 2023-05-26 |
1413618 | Security: Bug 1238631 regression (Share dialog on Windows can render over address bar, window controls) | $1,000 | 2023-05-23 |
1414511 | Security: ChromeOS root privilege escalation (mount-passthrough-jailed) | $31,000 | 2023-05-23 |
1414738 | Security: UAF in AppFinder::OnGetAppDescriptions | $31,000 | 2023-05-23 |
1400589 | Buffer overflow in the rndis_wlan driver for Linux kernel | $20,000 | 2023-05-22 |
1413945 | Security: Security DCHECK failed: IsA<Derived>(from) blink::LayoutMultiColumnFlowThread::ComputeSize layout_multi_column_flow_thread.cc:1666 | $8,000 | 2023-05-22 |
1413842 | flac_audio_handler_fuzzer: Global-buffer-overflow in media::AudioFifo::Consume | - | 2023-05-20 |
1414788 | Bad-cast to unsigned int (const void *) in FcHashTableFind | - | 2023-05-20 |
1401560 | Security: UAF in drm_gem_object_release_handle2 | $1,000 | 2023-05-19 |
1413005 | Security: A UAF in WebRTC | $2,000 | 2023-05-19 |
1413600 | Segv on unknown address in blink::LayoutObjectChildList::Trace | - | 2023-05-19 |
1409761 | Security: Race Condition Double Free in i915_gem_set_tiling_ioctl | $20,000 | 2023-05-17 |
1410942 | heap-use-after-free : nearby::connections::`anonymous namespace'::IncomingStreamInternalPayload::Close | - | 2023-05-17 |
1412020 | Security DCHECK failure: IsA<Derived>(from) in casting.h | - | 2023-05-17 |
1412629 | type mismatch with turboshaft,1 vs NaN | $7,000 | 2023-05-17 |
1413194 | Segv on unknown address in v8::internal::StackFrame::ComputeType | - | 2023-05-17 |
1413533 | DCHECK failure in iterator_.next_bytecode() == interpreter::Bytecode::kJumpIfUndefined in maglev-g | - | 2023-05-17 |
1413584 | safe_browsing_dmg_fuzzer: Trap in std::Cr::__libcpp_verbose_abort | - | 2023-05-17 |
1413651 | DCHECK failure in main-thread handle can only be created on the main thread in handles-inl.h | - | 2023-05-17 |
1293640 | Security: Linux Kernel i915 Linear Out-Of-Bound read and write access | - | 2023-05-15 |
1412643 | DCHECK failure in !MarkCompactCollector::IsOnEvacuationCandidate(target) in scavenger.cc | - | 2023-05-15 |
1412940 | v8_wasm_compile_fuzzer: DCHECK failure in !SlotInterference(target.stack_state[i], base::VectorOf(cache_state_.stack_state | - | 2023-05-15 |
1410766 | heap-buffer-overflow in aom_yv12_copy_v_c | $10,000 | 2023-05-14 |
1045681 | Security: Extension fingerprinting by detecting fetched resources | $1,000 | 2023-05-13 |
1382969 | Security: heap-use-after-free in observer_list.h triggered via Notes/Annotation feature | $1,000 | 2023-05-13 |
1398638 | Security: UAF in drm_gem_shmem_vm_close | - | 2023-05-13 |
1399742 | stack use after return in gpu::raster::(anonymous namespace)::OnReadYUVImagePixelsDone | $10,000 | 2023-05-13 |
1401562 | Security: UAF in drm_gem_object_release_handle3 | $21,000 | 2023-05-13 |
1401595 | Security: Race Condition UAF in i915_gem_context_getparam_ioctl | $21,000 | 2023-05-13 |
1406429 | v8 oobr on an obj | $7,000 | 2023-05-13 |
1411558 | Segv on unknown address in v8::internal::TracedHandlesImpl::Create | $9,000 | 2023-05-13 |
1411656 | CrOS: Vulnerability reported in media-libs/tiff | - | 2023-05-13 |
1412023 | boringssl_conf_fuzzer: Use-of-uninitialized-value in ASN1_template_free | - | 2023-05-13 |
1412233 | boringssl_conf_fuzzer: Heap-use-after-free in sk_num | - | 2023-05-13 |
1412236 | pdfium_fuzzer: Heap-use-after-free in CPDF_PageImageCache::StartGetCachedBitmap | - | 2023-05-13 |
1412309 | Use-after-poison in cppgc::internal::ConservativeTracingVisitor::TraceConservativelyIfNeeded | - | 2023-05-13 |
1412352 | boringssl_conf_fuzzer: Heap-use-after-free in sk_num | - | 2023-05-13 |
878351 | CrOS: Vulnerability reported in media-libs/tiff | - | 2023-05-10 |
1350740 | Security: access-violation on unknown address 0x12dfa490bbaa in dawn::native::TextureBase::TextureBase(browser process) | $5,000 | 2023-05-10 |
1354505 | Security: Hide real extension of file by many white spaces via suggestedName parameter - showSaveFilePicker | $1,000 | 2023-05-10 |
1394272 | Security: stack-use-after-scope in dawn::native::CommandEncoder::BeginRenderPass | $10,000 | 2023-05-10 |
1403515 | Heap Buffer Overflow in AudioWorkletProcessor::ClonePortTopology | $7,000 | 2023-05-10 |
1407595 | DCHECK failure in !object.InSharedHeap() in code-inl.h | - | 2023-05-10 |
1407701 | UAF in blink::VideoFrameSubmitter::OnContextLost | $3,000 | 2023-05-10 |
1410970 | Security: SEGV_ACCERR in Maglev | $7,000 | 2023-05-10 |
1411076 | DCHECK failure in old_.bytes_ >= bytes in array-buffer-sweeper.cc | - | 2023-05-10 |
1411153 | Security: Debug check failed: kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)) | $7,000 | 2023-05-10 |
1411533 | Crash in ProbeMemory | - | 2023-05-10 |
1412001 | Security: Potential security bug in JSCallReducer::ReduceDataViewAccess | - | 2023-05-10 |
1350329 | Security: UAFin CreateMdnsResponder | $2,000 | 2023-05-09 |
1406588 | Security: Heap-buffer-overflowREAD 1 in g_utf8_substring | - | 2023-05-09 |
1407095 | Debug check failed: !MarkCompactCollector::IsOnEvacuationCandidate(target). | - | 2023-05-09 |
1407955 | Security DCHECK failure: IsA<Derived>(from) in casting.h | $9,000 | 2023-05-09 |
1409217 | CrOS: Vulnerability reported in net-fs/samba | - | 2023-05-09 |
1411113 | DCHECK failure in collector == GarbageCollector::MINOR_MARK_COMPACTOR implies !pretenuring_handler | - | 2023-05-09 |
1401594 | Security: Race Condition UAF in i915_gem_context_create_ioctl | $21,000 | 2023-05-06 |
1258363 | URL Spoof after crash | $1,000 | 2023-05-05 |
1365100 | Security: Bypass iframe sandbox on Android via intent:// URLs (possibly due to intent:// url popups not inheriting sandbox) | $3,000 | 2023-05-05 |
1404621 | Security: Incognito Mode-specific external protocol prompts can be overlaid on other origins on Android. | $1,000 | 2023-05-05 |
1406032 | RendererAppContainer overwrites PROC_THREAD_ATTRIBUTE_CHILD_PROCESS_POLICY mitigation | - | 2023-05-05 |
1406162 | v8 crash in maglev::UseMarkingProcessor::MarkUse with maglev compiler | $7,000 | 2023-05-05 |
1407101 | Security: Debug check failed: result->owner() == owner (<unprintable> vs. <unprintable>). | - | 2023-05-05 |
1407342 | Security: Debug check failed: begin.valid(). | $7,000 | 2023-05-05 |
1407360 | Security: Debug check failed: entry->Is<InitialValue>(). | - | 2023-05-05 |
1407477 | Security: unreachable code in deoptimizer/translated-state.cc | - | 2023-05-05 |
1408354 | Security: Debug check failed: pred_reverse_index != -1 (-1 vs. -1) | $7,000 | 2023-05-05 |
837495 | Security: Heap Buffer Overflow found in stream_decoder.c of libFLAC used by chromium | - | 2023-05-03 |
1299235 | gpu_swangle_passthrough_fuzzer: Incorrect-function-pointer-type in rx::vk::PersistentCommandPool::init | - | 2023-05-03 |
1311885 | Security: heap-use-after-free ash/host/ash_window_tree_host_unified.cc | $2,000 | 2023-05-03 |
1409785 | DCHECK failure in code->IsBytecodeArray(cage_base) || code->GetCode().kind() == CodeKind::BASELINE | - | 2023-05-03 |
1410126 | Crash in ProbeMemory | - | 2023-05-03 |
1337747 | v8_inspector_fuzzer: Use-of-uninitialized-value in v8_crdtp::cbor::CBOREncoder::HandleInt32 | - | 2023-05-02 |
1348791 | Security: heap-use-after-free ash/drag_drop/drag_drop_controller.cc (Lacros) | $3,000 | 2023-05-02 |
1408392 | TALOS-2023-1693 - Google Chrome WebRTC RTCStatsCollector out of bounds memory access vulnerability | - | 2023-05-02 |
1408993 | Security: Security DCHECK failed: IsA<Derived>(from) blink::`anonymous namespace'::CalcToNumericValue:css_numeric_value.cc:162 | $8,000 | 2023-05-02 |
1409171 | heap-use-after-free : PrefService::RemovePrefObserver via ash::input_method::NativeInputMethodEngineObserver::~NativeInputMethodEngineObserver() | - | 2023-05-02 |
1409210 | DCHECK failure in !object.InSharedHeap() in code-inl.h | - | 2023-05-02 |
1409650 | Security: SwiftShader binaries are included in the following Dockerfile by just pulling them from a bucket | $2,000 | 2023-05-02 |
1394659 | DCHECK failure in code->IsCode(cage_base) implies code->kind(cage_base) == CodeKind::BASELINE in p | - | 2023-05-01 |
1408957 | Crash in ProbeMemory | - | 2023-05-01 |
1409225 | DCHECK failure in receiver == lookup_start_object in maglev-graph-builder.cc | - | 2023-05-01 |
1407045 | rtp_packet_fuzzer: Use-of-uninitialized-value in webrtc::ReadLeb128 | - | 2023-04-30 |
1406034 | memory corruption in blink::ReadableStreamDefaultControllerWithScriptScope::Enqueue | $3,000 | 2023-04-29 |
1274887 | Security: Autofill suggestion covers URL bar on Android | - | 2023-04-28 |
1346924 | Security: ResourceTiming entries are not generated for responses with 204, 205 status codes when loaded in a iframe | $2,000 | 2023-04-28 |
1398579 | Security: Android - Bypass the Protection of input fields cache (Autofill) | $5,000 | 2023-04-28 |
1403573 | oob in RTCStatsCollector::ProduceTransportStats_n | $2,000 | 2023-04-28 |
1406265 | UAP in blink::WebGPUSwapBufferProvider::DiscardCurrentSwapBuffer(with --enable-unsafe-webgpu) | $7,000 | 2023-04-28 |
1408467 | Crash in blink::HTMLFastPathParser<unsigned char>::ParseAttributes | $4,000 | 2023-04-28 |
1257537 | CrOS: Vulnerabilities reported in net-misc/curl | - | 2023-04-27 |
1341541 | Security: Bypass(1301873)Chrome for Android Hide Custom Fullscreen Toast View with Repeated delayed Enter Fullscreen Request | $4,000 | 2023-04-27 |
1386011 | UAF in MerchantViewerDataManager | $1,000 | 2023-04-27 |
1407571 | [TF::OptimizationBug] After optimization, running the "poc.js" yields segmentation fault | $7,000 | 2023-04-27 |
1048852 | Security: Leak of user's local IP address via unenforced Cross Site Origin policy and leak of networking timing | - | 2023-04-27 |
1404822 | FedCM privacy_policy_url and terms_of_service_url accepts arbitrary URL | - | 2023-04-26 |
1405123 | Google Chrome Console WebUI Heap-Overflow Vulnerability | $2,000 | 2023-04-26 |
1406115 | Out of bounds array access in SyncPointManager::GetSyncPointClientState() | - | 2023-04-26 |
1407930 | DCHECK failure in isolate->context().is_null() || isolate->context().IsContext() in runtime-intern | - | 2023-04-26 |
1408337 | v8_wasm_code_fuzzer: DCHECK failure in base::IsInBounds<uintptr_t>(offset, access_size, env_->module->max_memory_size) | - | 2023-04-26 |
1382477 | Security: Fenced frames: can use focus to communicate across the fenced frame boundary | - | 2023-04-25 |
1405574 | type confusion in chrome | $1,000 | 2023-04-25 |
1407606 | Crash in Builtins_Construct_WithFeedback | - | 2023-04-25 |
1404230 | Security: (Android) PWA Install prompt can be overlaid over other origins. | $2,000 | 2023-04-24 |
1406203 | DCHECK failure in clients_head_ == shared_heap_isolate_ in safepoint.cc | - | 2023-04-24 |
1406729 | Security: Debug check failed: old_entry.IsRegularEntry() in v8 | $8,000 | 2023-04-24 |
1400037 | Security: UAF in VIRTGPU_RESOURCE_CREATE and VIRTGPU_RESOURCE_CREATE_BLOB | $21,000 | 2023-04-23 |
1401666 | Security: sideload APKs on ChromeOS without enabling developer mode nor ADB | $3,000 | 2023-04-22 |
1405107 | Security: UAF in KAnonymityServiceSqlStorage::InitializeOnDbSequence | - | 2023-04-22 |
1405568 | Security: Race Condition Double Free in adreno_set_param | $21,000 | 2023-04-22 |
1406041 | Browser crashes when right clicking on input text | - | 2023-04-22 |
1407363 | Heap-use-after-free in blink::CharacterData::ContainsOnlyWhitespaceOrEmpty | - | 2023-04-22 |
1404864 | Security: Integer overflows in CountPages | $11,000 | 2023-04-21 |
1405256 | UAF in blink::RTCPeerConnectionHandler::OnIceCandidate | $3,000 | 2023-04-21 |
1406727 | Security: Debug check failed: kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)). | - | 2023-04-21 |
1406760 | template_url_parser_fuzzer: Heap-buffer-overflow in xmlParseTryOrFinish | - | 2023-04-21 |
1361204 | Security: heap-buffer-overflow components/ui_devtools/ui_element.cc:112:5 | $2,000 | 2023-04-20 |
1364115 | Security: UAF in device_is_authenticating | $500 | 2023-04-20 |
1382971 | Chrome_ChromeOS: Crash Report - content::RenderFrameHostImpl::CreateURLLoaderNetworkObserver | - | 2023-04-20 |
1400841 | Security: UAF in GuestViewBase::StopTrackingEmbedderZoomLevel | $7,000 | 2023-04-20 |
1401765 | Page background behind semi-transparent canvas leak content from other pages | - | 2023-04-20 |
1402920 | DCHECK failure in !value->IsShared() in objects.cc | - | 2023-04-20 |
1403539 | Security: PaymentRequest dialog selects an accept button by default | $5,000 | 2023-04-20 |
1403910 | Security: Debug check failed: IsJSObject(). | - | 2023-04-20 |
1404052 | Security: Debug check failed: ReadOnlyHeap::Contains(object) || heap_->Contains(object) | $7,000 | 2023-04-20 |
1404128 | Security: [maglev] Debug check failed: last_position.IsKnown() | - | 2023-04-20 |
1404704 | V8 type confusion of object as v8::Function in CallMethodOnFrame | $1,000 | 2023-04-20 |
1376011 | heap-use-after-free : lens::LensSidePanelController::~LensSidePanelController | - | 2023-04-18 |
1385343 | Security: Extension with <all_urls> permission can read arbitrary local files although (Allow access to file URLs) is disabled | $10,000 | 2023-04-18 |
1400522 | Security: heap-use-after-free in blink::PropertyTreeManager::EnsureCompositorTransformNode | $8,000 | 2023-04-18 |
1402921 | Crash in Builtins_ConstructProxy | - | 2023-04-18 |
1403129 | Security: Fatal error in ../../src/heap/mark-compact.cc | $7,000 | 2023-04-18 |
1404079 | Security: segmentation fault in ResizableArrayBuffer in v8 | $8,000 | 2023-04-18 |
1404123 | DCHECK failure in Shared heap must not have clients at teardown. The first isolate that is created | - | 2023-04-18 |
1405324 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts || (!MarkCompactCollector::IsOnEvacu | - | 2023-04-18 |
1394852 | Heap-use-after-free in v8::Isolate::IsInUse | - | 2023-04-17 |
1401525 | CHECK failure: external_page_bytes[t] == page->ExternalBackingStoreBytes(t) | - | 2023-04-17 |
1404652 | Crash in v8::internal::SamplingEventsProcessor::Run | - | 2023-04-17 |
1405157 | Heap-use-after-free in v8::Isolate::IsInUse | - | 2023-04-17 |
1405707 | DCHECK failure in current_code_reachable_and_ok_ == this->ok() && control_.back().reachable() in f | - | 2023-04-17 |
1404986 | Security DCHECK failure: IsA<Derived>(from) in casting.h | - | 2023-04-15 |
1405110 | Security: Heap-use-after-free in KAnonymityServiceSqlStorage::WaitUntilReady | - | 2023-04-15 |
1398989 | Security: ChromeOS On halt/reboot root file overwrite | $20,000 | 2023-04-14 |
1404639 | V8 type confusion of Undefined as v8::Function in ServiceWorkerGlobalScope::FetchHandlerType | $7,500 | 2023-04-14 |
1213778 | Security: Full screen notification overlap on Windows | - | 2023-04-13 |
1376354 | UAF in network::WebTransport::TearDown | $16,000 | 2023-04-13 |
1395354 | Security:UAF in content::SyntheticPointerAction::ForwardTouchOrMouseInputEvents(browser process) | $7,000 | 2023-04-13 |
1400809 | DCHECK failure in _is_listening_to_code_events == IsListeningToCodeEvents() in code-events.h | - | 2023-04-13 |
1402113 | Security: UAF in policy::DlpCopyOrMoveHookDelegate::RequestCopyAccess | $7,000 | 2023-04-13 |
1403531 | UAF in AsyncCompileJob::Abort | $10,000 | 2023-04-13 |
1405150 | DCHECK failure in element_size == 2 || element_size == 4 in maglev-ir-x64.cc | - | 2023-04-13 |
1372356 | Flaky uninitialized memory in SkChromeRemoteGlyphCache | - | 2023-04-12 |
1400113 | Security: Race Condition UAF in panfrost_ioctl_create_bo | $20,000 | 2023-04-12 |
1401965 | Security: Container-overflow in SavedTabGroupModel::RemoveTabFromGroup | $2,000 | 2023-04-12 |
1403546 | CHECK failure: !v8::internal::v8_flags.enable_slow_asserts || (IsSeqString_NonInline(*this)) in | - | 2023-04-12 |
1403574 | register assign error with jit | $7,000 | 2023-04-12 |
1381857 | Security: ChromiumOS CRAS Server D-Bus SetGlobalOutputChannelRemix heap-over-flow | $13,000 | 2023-04-11 |
1404299 | flexfec_receiver_fuzzer: Use-of-uninitialized-value in webrtc::RtpPacket::ParseBuffer | - | 2023-04-11 |
1403099 | DCHECK failure in !was_told_to_yield_ in default-job.h | - | 2023-04-10 |
1404232 | Heap-use-after-free in base::internal::CrashImmediatelyOnUseAfterFree | - | 2023-04-08 |
1401933 | Heap-use-after-free in content::RendererCancellationThrottle::NavigationCancellationWindowEnded | - | 2023-04-07 |
1320701 | CrOS: Vulnerability reported in sys-libs/ncurses | - | 2023-04-06 |
1403397 | flexfec_receiver_fuzzer: Use-of-uninitialized-value in webrtc::RtpPacket::ParseBuffer | - | 2023-04-06 |
1402000 | Security: heap-buffer-overflow in HidDeviceManager::GetApiDevicesFromList | $2,000 | 2023-04-05 |
1403168 | Security: Heap-use-after-free in ExtensionViewHost::OnDidStopFirstLoad | $4,000 | 2023-04-05 |
1401995 | Crash in content::GetDocumentUserData | - | 2023-03-31 |
1402660 | DCHECK failure in ((chunk->slot_set<OLD_TO_OLD, AccessMode::ATOMIC>())) == nullptr in mark-compact | - | 2023-03-31 |
1403399 | DCHECK failure in is_loadable() in maglev-ir.h | - | 2023-03-31 |
1160485 | Security: Access to camera with clickjacking and popup window | $2,000 | 2023-03-30 |
1385982 | Security: Escape the page sandbox to the Chromium debugger via Chrome headless snapshots | $2,000 | 2023-03-30 |
1398992 | Security: ChromeOS potential crosvm command execution via virgl_render_server (unexploitable) | $1,000 | 2023-03-30 |
1400048 | Security: Debug check failed: string->InSharedHeap() in v8 | $8,000 | 2023-03-30 |
1402270 | Debug check failed: value.IsForeign(). | $7,000 | 2023-03-30 |
1042963 | Security: bypass of CSP validator to run remote code in extensions | $3,000 | 2023-03-28 |
1395027 | Heap-use-after-free in blink::AXObject::ComputeIsInertViaStyle | - | 2023-03-28 |
1401996 | CHECK failure: !control->Is<JumpLoop>() in maglev-regalloc.cc | - | 2023-03-28 |
1402139 | CHECK failure: is_backed_by_rab == typed_array->is_backed_by_rab() in value-serializer.cc | - | 2023-03-28 |
1398987 | Security: ChromeOS debugd denial of service/service restart | - | 2023-03-27 |
1400257 | Use-of-uninitialized-value in v8::sampler::SamplerManager::DoSample | - | 2023-03-27 |
1401582 | 2 vulnerabilities reported in /third_party/libxml | - | 2023-03-27 |
1402011 | CHECK failure: non_atomic_marking_state()->IsWhite(obj) in mark-compact.cc | - | 2023-03-27 |
1402012 | Segv on unknown address in v8::internal::Heap::ExternalStringTable::TearDown | - | 2023-03-27 |
1402057 | CHECK failure: untyped_->count(slot.address()) > 0 in heap-verifier.cc | - | 2023-03-27 |
1383708 | Heap-buffer-overflow in Fill32BppDestStorageWithPalette | - | 2023-03-26 |
1396730 | Use-after-poison in content::InspectorMediaEventHandler::SendQueuedMediaEvents | $9,000 | 2023-03-25 |
1401295 | DCHECK failure in this->is_prototype_map() in map-inl.h | - | 2023-03-25 |
1401571 | Vulnerability reported in /third_party/dav1d | - | 2023-03-25 |
1401574 | 2 vulnerabilities reported in /third_party/libxml | - | 2023-03-25 |
813542 | Security: Web sites can open privileged pages via remote debugging server (CSRF) | $3,000 | 2023-03-24 |
1399331 | Crash in v8::internal::MemoryAllocator::LookupChunkContainingAddress | - | 2023-03-24 |
1400176 | GetEntriesWithChildFrames exposes top-level same origin iframes to cross-origin ones | - | 2023-03-24 |
1401528 | DCHECK failure in entry.IsRegularEntry() in external-pointer-table-inl.h | - | 2023-03-24 |
1394968 | DCHECK failure in Shared heap must not have clients at teardown. The first isolate that is created | - | 2023-03-23 |
1400730 | Use-of-uninitialized-value in v8::internal::MarkingBarrier::Write | - | 2023-03-23 |
1401069 | CHECK failure: untyped_->count(slot.address()) > 0 in heap-verifier.cc | - | 2023-03-23 |
1401077 | DCHECK failure in ReadOnlyHeap::Contains(obj) || heap()->Contains(obj) in mark-compact-inl.h | - | 2023-03-23 |
1401078 | CHECK failure: external_page_bytes[t] == page->ExternalBackingStoreBytes(t) | - | 2023-03-23 |
1401180 | DCHECK failure in !heap_->always_allocate() in incremental-marking.cc | - | 2023-03-23 |
1401181 | CHECK failure: InTypedSet(SlotType::kEmbeddedObjectFull, rinfo->pc()) || InTypedSet(SlotType::k | - | 2023-03-23 |
1401183 | CHECK failure: IsValidHeapObject(heap_, heap_object) in heap-verifier.cc | - | 2023-03-23 |
1401336 | CHECK failure: InTypedSet(SlotType::kEmbeddedObjectFull, rinfo->pc()) || InTypedSet(SlotType::k | - | 2023-03-23 |
1401337 | CHECK failure: IsValidHeapObject(heap_, heap_object) in heap-verifier.cc | - | 2023-03-23 |
1361294 | CrOS: Vulnerability reported in net-wireless/bluez | - | 2023-03-22 |
1386095 | CrOS: Vulnerability reported in media-libs/tiff | - | 2023-03-22 |
1394279 | DCHECK failure in code == topmost_ implies safe_to_deopt_ in deoptimizer.cc | - | 2023-03-22 |
1394408 | Security: Debug check failed: enum_length == map->NumberOfEnumerableProperties() | $11,000 | 2023-03-22 |
1394973 | Fatal error in Bytecode mismatch at offset 2 in interpreter.cc | - | 2023-03-22 |
1395604 | Abrt in v8::internal::abort_with_reason | - | 2023-03-22 |
1397348 | memory corruption in v8 | $7,000 | 2023-03-22 |
1398994 | Security: ChromeOS CrosDisks mount-zip fuse argument injection | $1,000 | 2023-03-22 |
1399379 | DCHECK failure in ThreadId::Current() == thread_id() in isolate.cc | - | 2023-03-22 |
1399424 | v8_wasm_fuzzer: Crash in v8::internal::Simulator::WriteW | - | 2023-03-22 |
1399511 | Security: UAF in MojoQueryQuotaIpcz | $30,000 | 2023-03-22 |
1399799 | CHECK failure: !destination.IsDetachedOrOutOfBounds() in elements.cc | - | 2023-03-22 |
1399805 | Crash in Builtins_PromiseRejectReactionJob | - | 2023-03-22 |
1399904 | Security: Container Overflow in UDPSocket::OnLeaveGroupCompleted | $10,000 | 2023-03-22 |
1400054 | Bad-cast to mojo::core::ipcz_driver::ObjectBase from ipcz::ParcelWrapper in mojo::core::ipcz_driver::Object<mojo::core::ipcz_driver::DataPipe>::FromHandle | - | 2023-03-22 |
1400062 | CrOS: Vulnerability reported in net-misc/curl | - | 2023-03-22 |
1400431 | v8_serialized_script_value_fuzzer: Heap-buffer-overflow in v8::internal::ValueDeserializer::ReadJSArrayBuffer | - | 2023-03-22 |
1400549 | DCHECK failure in frame->is_unoptimized() in frames.h | - | 2023-03-22 |
1400551 | DCHECK failure in pred_reverse_index != -1 in graph.h | - | 2023-03-22 |
1400810 | DCHECK failure in 0 < level_ in mutex.h | - | 2023-03-22 |
1400051 | Security: Debug check failed: Shared heap must not have clients at teardown, leading to SEGV_ACCERR | $8,000 | 2023-03-19 |
1385941 | DCHECK failure in !initializing_store && property_details_.constness() == PropertyConstness::kCons | - | 2023-03-18 |
1393499 | Security: UAF in drm_gem_object_release_handle | $2,000 | 2023-03-18 |
1395029 | CrOS: Vulnerability reported in dev-libs/libxml2 | - | 2023-03-18 |
1399080 | Security: libtiff CVE vulnerabilities in Chromium 106.0.5249.103 | $500 | 2023-03-18 |
1399328 | Crash in v8::internal::BasicMemoryChunk::area_start | - | 2023-03-18 |
1399330 | CHECK failure: untyped_->count(slot.address()) > 0 | - | 2023-03-18 |
1399488 | Crash in v8::internal::LookupIterator::Start<0> | - | 2023-03-18 |
1399489 | CHECK failure: index < size() | - | 2023-03-18 |
1399491 | Crash in void v8::internal::MarkingVisitorBase<v8::internal::ConcurrentMarkingVisitor, v8 | - | 2023-03-18 |
1399696 | CHECK failure: value__value.IsJSReceiver() || value__value.IsSmi() || value__value.IsHeapNumber | - | 2023-03-18 |
866311 | Security: Google Update for Windows allows arbitrary file creation when logs are enabled | $5,000 | 2023-03-16 |
1083278 | Security: DNS Cache Poisoning through resource exhaustion in Chrome. | $5,000 | 2023-03-16 |
1357366 | Sandbox bypass "allow-downloads" | $3,000 | 2023-03-16 |
1384737 | AppCommands: perhaps deprecate older command format | - | 2023-03-16 |
1393547 | DCHECK failure in IsInRegister(target_state, incoming) in maglev-regalloc.cc | - | 2023-03-16 |
1395603 | DCHECK failure in !value->allocation().IsConstant() in maglev-assembler-x64-inl.h | - | 2023-03-16 |
1395718 | Security: UAF in HandleExpandedPaths | $31,000 | 2023-03-16 |
1399332 | DCHECK failure in heap()->non_atomic_marking_state()->IsWhite(target) in scavenger-inl.h | - | 2023-03-16 |
1399377 | CHECK failure: external_page_bytes[t] == page->ExternalBackingStoreBytes(t) | - | 2023-03-16 |
1378233 | CrOS: Vulnerability reported in dev-libs/libtasn1 | - | 2023-03-15 |
1396254 | Security: CVE-2022-3970 was fixed in libtiff and published but not propagated to Pdfium yet | $1,000 | 2023-03-15 |
1057218 | Security: Implement Resource Isolation with Random Restricted SIDs | - | 2023-03-14 |
1392661 | Security: heap-use-after-free drop_target_event.cc:28 in ui::DropTargetEvent::DropTargetEvent | $5,000 | 2023-03-14 |
1395542 | Security: heap-use-after-free third_party/swiftshader/src/WSI/VkSwapchainKHR.cpp:43:13 | $2,000 | 2023-03-14 |
1396222 | Security: Fatal error in ../../src/heap/sweeper.cc | $7,000 | 2023-03-14 |
1396338 | Crash in v8::internal::HeapObject::SizeFromMap | - | 2023-03-14 |
1396339 | CHECK failure: marking_state_->IsBlack(heap_object) in mark-compact.cc | - | 2023-03-14 |
1396341 | Use-of-uninitialized-value in v8::internal::MarkingBarrier::Write | - | 2023-03-14 |
1396342 | DCHECK failure in handle & ~kVisitedHandleMarker == index << kExternalPointerIndexShift in externa | - | 2023-03-14 |
1396344 | DCHECK failure in page->area_size() >= static_cast<size_t>(marking_state_->live_bytes(page)) in sw | - | 2023-03-14 |
1018214 | Security: Updated Google Password. One of my Chrome OS machines still takes the old password though after over a week | $1,000 | 2023-03-13 |
1384403 | DCHECK failure in GetCurrentStackPosition() >= stack_guard()->real_climit() - 8 * KB in isolate.cc | - | 2023-03-13 |
1394741 | DCHECK failure in isolate()->thread_id() == ThreadId::Current() in heap.cc | - | 2023-03-13 |
1395117 | Crash in v8::internal::JsonParser<unsigned char>::ParseJson | - | 2023-03-13 |
1395237 | Heap-use-after-free in v8::internal::NodeBase<v8::internal::GlobalHandles::Node>::index | - | 2023-03-13 |
1395520 | CHECK failure: untyped_->count(slot.address()) > 0 | - | 2023-03-13 |
1395737 | DCHECK failure in LocationOperand::cast(source)->IsCompatible( LocationOperand::cast(destination)) | - | 2023-03-13 |
1371859 | stack-use-after-return in gpu::gles2::ProgramInfoManager::Program::UpdateES2 | $3,000 | 2023-03-12 |
1383991 | blink::MediaInspectorContextImpl::CullPlayers | $7,000 | 2023-03-12 |
1395311 | CHECK failure: !base::IsInRange(slot.address(), start, end + 1) in remembered-set.h | - | 2023-03-12 |
840716 | Unicode Line Terminators Can Cause UI Manipulation and Browser Crashes | - | 2023-03-10 |
1385831 | UAF in CartService | $2,500 | 2023-03-10 |
1392721 | Security: heap-use-after-free on chromeOS using PhoneHub + Screensharing | $2,000 | 2023-03-10 |
1393384 | webcodecs_video_encoder_fuzzer: Heap-buffer-overflow in av1_get_one_pass_rt_params | - | 2023-03-10 |
1393564 | Security: UAF in content::NavigationRequest::SetViewTransitionState in browser process | $20,000 | 2023-03-10 |
1394382 | Chromium: Vulnerability reported in third_party/libxml | - | 2023-03-10 |
1395183 | Crash in v8::internal::SpaceWithLinearArea::InvokeAllocationObservers | - | 2023-03-10 |
1395186 | Chromium: Vulnerability reported in third_party/libxml | - | 2023-03-10 |
1395240 | Crash in Builtins_JSEntryTrampoline | - | 2023-03-10 |
1349146 | Security: Source maps support for file:// URLs gives devtools_page extensions local file access | $5,000 | 2023-03-09 |
1365366 | Security: [maglev] VisitSwitchOnGeneratorState function JumpTableTargetOffsets can be 0 | $7,000 | 2023-03-09 |
1380645 | Security: Use After Free in PasswordsPrivateDelegateImpl::OsReauthTimeoutCall, | $1,000 | 2023-03-09 |
1382484 | Security: Chrome on Android Keyboard Able to Overlap Fullscreen Notification Toast | $7,500 | 2023-03-09 |
1392588 | Security: Security DCHECK failed: IsA<Derived>(from) blink::CSSPrimitiveValue::ConvertToLength | $8,000 | 2023-03-09 |
1393728 | Security: stack-use-after-scope in dawn::native::d3d12::ShaderModule::Compile | $10,000 | 2023-03-09 |
1393732 | Security: Download notification can hide "Press and hold Esc to exit full screen" | $3,000 | 2023-03-09 |
1393865 | Turbofan-Optimization Bug: "Check failed: IsBigInt()" | $7,000 | 2023-03-09 |
1394692 | UAF in OnSyncMessageEventReady | $6,000 | 2023-03-09 |
1384516 | gpu_raster_fuzzer: Use-of-uninitialized-value in cc::ServiceImageTransferCacheEntry::Deserialize | - | 2023-03-08 |
1385368 | Security: Debug check failed: s->IsFlat(). | $7,000 | 2023-03-08 |
1393227 | Security: dcheck failed in object.InSharedHeap | $7,000 | 2023-03-08 |
1393270 | Crash in v8::internal::IsPrimitiveHeapObject_NonInline | - | 2023-03-08 |
1393733 | CHECK failure: InstructionBlockAt(predecessor_id)->IsDeferred() in instruction.cc | - | 2023-03-08 |
1393940 | CHECK failure: is_int8(disp) in assembler-x64.cc | - | 2023-03-08 |
1394036 | CHECK failure: !control->Is<JumpLoop>() in maglev-regalloc.cc | - | 2023-03-08 |
1394403 | Security: [0-day] FeedbackCell issue leading to type confusion | - | 2023-03-08 |
1246736 | Security: Imagination PowerVR DRM Driver Integer overflow vulnerabilities on MTK platform Chromebook | $20,000 | 2023-03-07 |
1350386 | Security: UAF in ArcInputOverlayManager::ReadDefaultData | - | 2023-03-07 |
1356760 | Reject hidden name-only cookie prefixes | - | 2023-03-07 |
1370562 | uaf in ui::PropertyHandler::GetPropertyInternal(with ) | $2,000 | 2023-03-07 |
1375131 | Security: Unknown crash with READ of size 8 when access the chrome://gpu with WebGPU enabled | - | 2023-03-07 |
1380602 | Security: heap-use-after-free ui/views/view.cc:1921:7 in views::View::HandleAccessibleAction | $2,000 | 2023-03-07 |
1383442 | Security: UAF IN video_capture::VideoSourceImpl::OnClientDisconnected() services/video_capture/video_source_impl.cc:88:14 | $16,000 | 2023-03-07 |
1386120 | Security: Pdfium heap-buffer-overflow in RgbByteOrderTransferBitmap() | - | 2023-03-07 |
1386122 | Security: heap-buffer-overflow in CFX_DIBBase::SwapXY() | - | 2023-03-07 |
1386123 | Security: Pdfium heap-buffer-overflow in RgbByteOrderTransferBitmap() | - | 2023-03-07 |
1386124 | Security: Pdfium heap-buffer-overflow in CPDF_RenderStatus::LoadSMask() | - | 2023-03-07 |
1392061 | Security: Debug check failed: IsPrimitiveMap() | $10,000 | 2023-03-07 |
1393097 | mhtml_parser_fuzzer: Heap-buffer-overflow in modp_b64_decode | - | 2023-03-07 |
1393177 | Security: WebGPU UAF in Dawn Memory Transfer Service | - | 2023-03-07 |
1392755 | DCHECK failure in isolate()->thread_id() == ThreadId::Current() in heap.cc | - | 2023-03-06 |
1392934 | v8_wasm_async_fuzzer: DCHECK failure in has_index() in value-type.h | - | 2023-03-06 |
1393468 | gpu_swangle_passthrough_fuzzer: Segv on unknown address in __tls_get_addr | - | 2023-03-05 |
1393375 | Security: Read OOB due to resizing underline typed array buffer | - | 2023-03-03 |
1393464 | DCHECK failure in handle & ~kVisitedHandleMarker == index << kExternalPointerIndexShift in externa | - | 2023-03-03 |
1381871 | UAF in blink::WidgetBase::BeginMainFrame(base::TimeTicks) | $1,500 | 2023-03-02 |
1382761 | UAF in search::(anonymous namespace)::NewTabURLDetails::ForProfile(Profile*) | $3,000 | 2023-03-02 |
1386249 | Security: Unretained() can be used for objects on the Oilpan heap | $3,000 | 2023-03-02 |
1386667 | Negative-size-param in ipcz::BlockAllocator::InitializeRegion | - | 2023-03-02 |
1392585 | Crash in Builtins_ConstructProxy | - | 2023-03-02 |
1392865 | CHECK failure: InTypedSet(SlotType::kEmbeddedObjectFull, rinfo->pc()) || InTypedSet(SlotType::k | - | 2023-03-02 |
1392936 | DCHECK failure in receiver_mode_ != ConvertReceiverMode::kNullOrUndefined in maglev-graph-builder. | - | 2023-03-02 |
1392953 | Optimization bug in TurboShaft::MachineOptimizationReducer::ReduceSignedDiv | $10,000 | 2023-03-02 |
1316301 | DCHECK failure at blink::WebFrameWidgetImpl::DragTargetDragEnter | $1,500 | 2023-03-01 |
1382033 | Security: heap-buffer-overflow in network::ThrottlingNetworkInterceptor::UpdateThrottledRecords | $2,000 | 2023-03-01 |
1385709 | UAF in CartHandler | $2,500 | 2023-03-01 |
1386121 | Security: Pdfium heap-buffer-overflow in CFX_BitmapComposer::ComposeScanlineV() | - | 2023-03-01 |
1392577 | Security: Debug Check end <= typed_aray->GetLength() | - | 2023-03-01 |
1392589 | substring_set_matcher_fuzzer: Crash in base::SubstringSetMatcher::AhoCorasickNode::SetEdge | - | 2023-03-01 |
1392715 | Security: heap-buffer-overflow in gpu::gles2::Texture::SetLevelCleared | - | 2023-03-01 |
1385691 | Security: global-buffer-overflow css_property.cc:27 in blink::CSSProperty::Get | $7,000 | 2023-02-28 |
1385717 | Security: Debug check failed: slot < sentinel_ in UpdateUntypedOldToSharedPointers | $8,000 | 2023-02-28 |
1386647 | tint_regex_msl_writer_fuzzer.exe: Illegal-instruction in tint::Program::Program | - | 2023-02-28 |
1386129 | substring_set_matcher_fuzzer: Heap-buffer-overflow in base::SubstringSetMatcher::AhoCorasickNode::SetEdge | - | 2023-02-27 |
1386287 | DCHECK failure in result.valid() in optimization-phase.h | - | 2023-02-27 |
1387883 | DCHECK failure in bytecode_offset >= kFunctionEntryBytecodeOffset in factory.cc | - | 2023-02-27 |
1388938 | v8_wasm_streaming_fuzzer: DCHECK failure in sub_module->has_type(sub_index) in wasm-subtyping.cc | - | 2023-02-27 |
1386649 | audio_encoder_isac_float_fuzzer.exe: Stack-buffer-overflow in webrtc::AudioEncoderIsacT<webrtc::IsacFloat>::EncodeImpl | - | 2023-02-26 |
1360743 | Security: heap-use-after-free in the Metal features in the GPU process | $1,000 | 2023-02-25 |
1369205 | Tests are failing: Verify that the placeholder <canvas> associated with an OffscreenCanvas tainted with cross-origin content cannot be read once commit has propagated... | - | 2023-02-25 |
1382074 | ui_x11_cursor_loader_fuzzer: Heap-buffer-overflow in ui::ParseCursorFile | - | 2023-02-25 |
1383203 | DCHECK failure in input_count <= std::numeric_limits<decltype(this->input_count)>::max() in operat | - | 2023-02-25 |
1384847 | Revisit configurations for CoInitializeSecurity calls | - | 2023-02-25 |
1385673 | DCHECK failure in IsJSFunction() in heap-refs.cc | - | 2023-02-25 |
1385935 | DCHECK failure in page->area_size() >= static_cast<size_t>(marking_state_->live_bytes(page)) in sw | - | 2023-02-25 |
1379359 | MTLDeviceProxy does not properly copy NSStrings | - | 2023-02-23 |
1155961 | wildcard entry with runtime_blocked_hosts in ExtensionSettings policy is not enforced correctly | - | 2023-02-22 |
1339079 | Security: GPU process continues running even if we fail to initialize the sandbox | - | 2023-02-22 |
1378564 | Use-after-free in Mojo ChannelMac::SendMessageLocked | $30,000 | 2023-02-22 |
1381849 | Memory corruption in PresentationRequest | $8,500 | 2023-02-22 |
1383755 | tint_ast_clone_fuzzer: Heap-use-after-free in tint::utils::HashmapBase<tint::sem::Type const*, tint::Source const*, 8ul, tint: | - | 2023-02-22 |
1383976 | DCHECK failure in !initializing_store && property_details_.constness() == PropertyConstness::kCons | - | 2023-02-22 |
1384318 | DCHECK failure in value->Is<Int32Constant>() || value->Is<StringLength>() || value->Is<BuiltinStri | - | 2023-02-22 |
1384408 | Crash in v8::internal::Invoke | - | 2023-02-22 |
1384411 | Crash in Builtins_StringSubstring | - | 2023-02-22 |
1384474 | DCHECK failure in count <= destination.GetLength() in elements.cc | - | 2023-02-22 |
1384513 | Stack-use-after-return in blink::NGConstraintSpaceBuilder::NGConstraintSpaceBuilder | - | 2023-02-22 |
1384765 | Check return from AddAllowedAce in ServiceMain::InitializeComSecurity | - | 2023-02-22 |
1384796 | Maybe use PROCESS_QUERY_LIMITED_INFORMATION in LegacyProcessLauncherImpl::LaunchCmdElevated | - | 2023-02-22 |
1385291 | DCHECK failure in kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)) in tagged-impl.h | - | 2023-02-22 |
1385305 | Segv on unknown address in Builtins_InterpreterEntryTrampoline | - | 2023-02-22 |
1238642 | Security: Refcount overflow in RefCountedThreadSafeBase | $1,000 | 2023-02-21 |
1368230 | Security: SameSite cookie bypass on Android by redirecting to to intent-picker | $5,000 | 2023-02-21 |
1378357 | Security: Avast aswJsFlt.dll 18.0.1479.0 exposes vulnerable pipe endpoint to renderers | - | 2023-02-21 |
1382363 | UAF in AppIconReader | $2,000 | 2023-02-21 |
1382581 | Security: UAF in validation_message_overlay_delegate | $7,000 | 2023-02-21 |
1383204 | Trap in Builtins_CheckTurbofanType | - | 2023-02-21 |
1383422 | Security: Heap-buffer-overflow in CommerceHintAgent::DidFinishLoadCallback | $2,500 | 2023-02-21 |
1383791 | Security: UAF in lens::LensStaticPageController::LoadChromeLens | $4,000 | 2023-02-21 |
1384520 | Crash in Builtins_StringEqual | - | 2023-02-21 |
1371215 | Security: Forced user interaction for permission prompts by freezing the browser | $3,000 | 2023-02-20 |
1379860 | DCHECK failure in !HAS_WEAK_HEAP_OBJECT_TAG(ptr_) in tagged-impl-inl.h | - | 2023-02-20 |
1381763 | CrOS: Vulnerability reported in x11-libs/pixman | - | 2023-02-20 |
1372019 | Security: ClientNativePixmapFactory implementations are probably not validating enough and should use checked math | - | 2023-02-18 |
1344756 | Security: Heap-use-after-free in ReadAnythingCoordinator::CreateAndRegisterEntry | $4,000 | 2023-02-17 |
1381094 | Security: UAF in DlpScopedFileAccessDelegate::OnResponse | - | 2023-02-17 |
1381217 | Security: Bypass 1342722, sourceMappingURL directive allows use of UNC paths on Windows | $5,000 | 2023-02-17 |
1382652 | Security: global-buffer-overflow in ash::default_user_image::GetRandomDefaultImageIndex() | - | 2023-02-17 |
1382816 | v8_wasm_code_fuzzer: DCHECK failure in opcode >> 8 == kNumericPrefix in function-body-decoder-impl.h | - | 2023-02-17 |
1382993 | Security: UAF in content::RenderFrameDevToolsAgentHost::RenderProcessExited | $31,000 | 2023-02-17 |
1383362 | DCHECK failure in type == MachineType::Int32() || type == MachineType::Uint32() || type.representa | - | 2023-02-17 |
1383367 | DCHECK failure in value->Is<Int32Constant>() || value->Is<StringLength>() || value->Is<BuiltinStri | - | 2023-02-17 |
1383369 | Crash in v8::internal::maglev::GetInputLocationsArraySize | - | 2023-02-17 |
1383374 | Crash in Builtins_ConstructProxy | - | 2023-02-17 |
1375021 | uaf in FederatedAuthRequestImpl | $10,000 | 2023-02-16 |
1376995 | uaf in FederatedAuthRequestimpl | $10,000 | 2023-02-16 |
1377165 | Reading local files through an extension that only has the "downloads" permission | $5,000 | 2023-02-16 |
1380860 | gl_lpm_fuzzer: Use-of-uninitialized-value in wsi_unsupported_instance_extension | - | 2023-02-16 |
1382369 | UAF in ScreenAIService | $2,500 | 2023-02-16 |
1382434 | Security: Copy-on-write check bypass in JSNativeContextSpecialization::BuildElementAccess | - | 2023-02-16 |
1382690 | UAF in ScreenAIServiceRouter | $5,000 | 2023-02-16 |
1377783 | Security: heap-use-after-free in StreamFactory::DestroyMuter | - | 2023-02-15 |
1378601 | webcodecs_video_encoder_fuzzer: Heap-buffer-overflow in aom_variance64x64_avx2 | - | 2023-02-15 |
1381335 | Security: Debug check failed: kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)). | $11,000 | 2023-02-15 |
1381401 | Security: UAF in VideoCaptureDeviceWin | $11,000 | 2023-02-15 |
1358647 | Security: Bypass the Protection of input fields cache (Autofill) 1108181 | $5,000 | 2023-02-14 |
1367632 | Security: Extension sanitization bypass by using %% | $2,000 | 2023-02-14 |
1376099 | Security: Design flaw in Synchronous Mojo message handling introduces unexpected reentrancy and allows for multiple UAFs | - | 2023-02-14 |
1379242 | UAF in ExtensionInstalledWaiter | $2,000 | 2023-02-14 |
1380751 | CrOS: Vulnerability reported in net-vpn/strongswan | - | 2023-02-14 |
1382423 | Trap in Builtins_CheckTurbofanType | - | 2023-02-14 |
1358505 | Security: V8: Missing TurboFan bounds check on DataView when buffer is resizable | - | 2023-02-13 |
1365053 | CHECK failure: result.failed() implies v8_flags.wasm_lazy_validation in module-compiler.cc | - | 2023-02-13 |
1379579 | Security: heap-use-after-free browser\renderer_host\render_process_host_impl.cc:2068 in content::RenderProcessHostImpl::CreateNotificationService | $8,000 | 2023-02-13 |
1381330 | v8_wasm_async_fuzzer: DCHECK failure in opcode >> 8 == kAtomicPrefix in function-body-decoder-impl.h | - | 2023-02-13 |
1381663 | Crash in v8::internal::maglev::InterpreterFrameState::get | - | 2023-02-13 |
1381665 | DCHECK failure in count() > 0 in maglev-graph-builder.h | - | 2023-02-13 |
1326788 | Security: Lackluster "File System Access API" block-list provides full disk read/write access | $1,000 | 2023-02-10 |
1359122 | Security: SOP bypass leaks navigation history of iframe from other subdomain if location changed to about:blank | $2,000 | 2023-02-10 |
1372457 | Possible vulnerability in crosvm: Invalid check for Virtio descriptors | - | 2023-02-10 |
1378457 | Security: UAF in PasswordAutofillManager::OnBiometricReauthCompleted | $7,000 | 2023-02-10 |
1378813 | extension_file_highlighter_fuzzer: Trap in std::Cr::__libcpp_verbose_abort | - | 2023-02-10 |
1378997 | Security: FileChooserImpl still traverse symlink in symlink to directory | $3,000 | 2023-02-10 |
1380398 | Crash in Builtins_StringEqual | - | 2023-02-10 |
1380498 | v8_wasm_code_fuzzer: DCHECK failure in a == b in liftoff-assembler.cc | - | 2023-02-10 |
956979 | Mixed content can be bypassed by sandboxed pages | $1,000 | 2023-02-09 |
1359678 | CrOS: Vulnerability reported in media-libs/tiff | - | 2023-02-09 |
1377610 | CrOS: Vulnerability reported in media-libs/tiff | - | 2023-02-09 |
1377790 | Security: CSA_DCHECK failed: Torque assert 'remainingElementsCount >= 0' failed in v8 | - | 2023-02-09 |
1379740 | Security DCHECK failure: unit.TextContentEnd() <= text.length() in ng_offset_mapping.cc | - | 2023-02-09 |
1380478 | Security: clang-analyzer-cplusplus.NewDelete in third_party/pdfium/core/fpdfapi/parser/cpdf_object_walker.cpp | - | 2023-02-09 |
1352445 | Security: heap-use-after-free in password_manager::WellKnownChangePasswordState::SetChangePasswordResponseCode | - | 2023-02-08 |
1356987 | Security: External notifications from external apps (such as Telegram) can block Android fullscreen notification. (Testes on latest Chrome stable) | $2,000 | 2023-02-08 |
1375132 | Security: Android: Bluetooth and USB chooser dialogs do not use top-level origin with permission delegation | $3,000 | 2023-02-08 |
1378456 | Security: UAF in PasswordAutofillManager::DidAcceptSuggestion | - | 2023-02-08 |
1378814 | DCHECK failure in properties().can_eager_deopt() in maglev-ir.h | - | 2023-02-08 |
1378916 | Security: local IP address disclosure using WebRTC candidate foundation | - | 2023-02-08 |
1379054 | Security: Promise.any.call leak hole, leading to RCE | $15,000 | 2023-02-08 |
1379201 | Security: Stack-buffer-overflow in WebGL vulkan backend | $11,000 | 2023-02-08 |
1379364 | DCHECK failure in IsImmAddSub(frame_size) in liftoff-assembler-arm64.h | - | 2023-02-08 |
1379468 | DCHECK failure in 0 != new_nodes_.count(value) in maglev-graph-builder.h | - | 2023-02-08 |
1379831 | Security: stack-buffer-overflow in mojo::core::ipcz_driver::ObjectBase::PeekBox(browser process) | - | 2023-02-08 |
1379864 | DCHECK failure in new_target->IsConstructor() in js-objects.cc | - | 2023-02-08 |
1380313 | Use-after-poison in blink::CSSSelector::SelectorListOrParent | $12,000 | 2023-02-08 |
1370028 | Security: Chrome on Android the Fullscreen Notification Toast Not shown when fullscreen (screen lock mode landscape) | $5,000 | 2023-02-06 |
1374995 | Trap in Builtins_CheckTurbofanType | - | 2023-02-03 |
1375073 | DCHECK failure in constructor->IsNull(isolate) in runtime-classes.cc | - | 2023-02-03 |
1378571 | Security: UAF in MultiplexEncoderFactory | $11,000 | 2023-02-03 |
1345045 | CSP Bypass (Old Issue) | $3,000 | 2023-02-02 |
1371844 | Security: UAF in PluginVmInstaller::DetectImageType | $1,000 | 2023-02-02 |
1374746 | CHECK failure: proto.map().oddball_type() == OddballType::kNull in compilation-dependencies.cc | - | 2023-02-02 |
1377775 | Crash in Builtins_StringIndexOf | - | 2023-02-02 |
1377816 | Security: WebAssembly UAF in catch block with stale memory start pointer | $21,000 | 2023-02-02 |
1377840 | Security: Incorrect rab flags setting leads to type confusion in V8 | - | 2023-02-02 |
1378286 | Security: Heap-use-after-free in InstallablePaymentAppCrawler::OnPaymentMethodManifestParsed | $39,000 | 2023-02-02 |
1378287 | Security: Heap-use-after-free in ChromeAutofillClient::DidFinishNavigation | - | 2023-02-02 |
1378323 | compositor_frame_fuzzer: Global-buffer-overflow in gfx::Transform::RotateAboutZAxis | - | 2023-02-02 |
1365877 | Security: Esc doesn't exit fullscreen in Crostini apps | - | 2023-02-01 |
1374294 | Security: access-violation src\v8\src\api\api.cc:5809 in v8::String::WriteOneByte | $5,000 | 2023-02-01 |
1378437 | Crash in Builtins_Construct_WithFeedback | - | 2023-02-01 |
1378494 | Crash in Builtins_StringSubstring | - | 2023-02-01 |
1378495 | Crash in Builtins_InterpreterEntryTrampoline | - | 2023-02-01 |
1340924 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1343339 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1344118 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1344821 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1346256 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1346675 | Security: UTF chartorune heap-buffer-overflow crash | $8,000 | 2023-01-31 |
1361911 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1362225 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1362331 | Generic CORS bypass that enables Cross-Site-Tracing (XST) | $1,000 | 2023-01-31 |
1363579 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1366771 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1367617 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1368560 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1369956 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1370293 | CrOS: Vulnerability reported in app-editors/vim | - | 2023-01-31 |
1372757 | Security: Heap-use-after-free in ash::OverviewItem::ShowWindowInOverview | $1,500 | 2023-01-31 |
1378168 | Use-of-uninitialized-value in v8::internal::compiler::BranchElimination::SimplifyBranchCondition | - | 2023-01-31 |
1368739 | Security: FencedFrame - Two way communication between embedder and frame | $6,000 | 2023-01-30 |
1251790 | Security: Top-level redirect from cross-origin iframe by setting `Content-Security-Policy: sandbox allow-top-navigation` | $5,000 | 2023-01-28 |
1375059 | Multiple checks fail, cross process crash, maybe race condition & use-after-free in video_encoder.cc | $7,000 | 2023-01-28 |
1303597 | Heap-use-after-free in blink::BoxPainterBase::PaintFillLayer | $10,000 | 2023-01-27 |
1342072 | Security: Presentation API dialog unexpectedly shows top-level origin when called by cross-origin iframe without explicit allow-presentation delegation | $7,500 | 2023-01-27 |
1361066 | Security: OOB write on Lacros | $2,000 | 2023-01-27 |
1365945 | Security: UAF in ash::network_diagnostics::DnsResolutionRoutine::CreateHostResolver() (browser process) | $3,000 | 2023-01-27 |
1376856 | Crash in Builtins_Construct_WithFeedback | - | 2023-01-27 |
1376930 | CHECK failure: BigIntNegate of kRepTaggedPointer (BigInt) cannot be changed to kRepTaggedPointe | - | 2023-01-27 |
1377250 | UaF in PRM observerlist after browser change (confirmation chip) | - | 2023-01-27 |
985740 | CrOS: Vulnerability reported in sys-libs/glibc | - | 2023-01-25 |
1372746 | Security: Heap-use-after-free in ash::ScopedOverviewHideWindows::~ScopedOverviewHideWindows | $2,000 | 2023-01-25 |
1373941 | Security: heap-use-after-free in ProfileDestroyer::DestroyProfileNow | $2,000 | 2023-01-25 |
1374513 | Security: Bypass powerwash using factory_install_reset file | - | 2023-01-25 |
1375088 | Security: UAF in webgpu\gpu.cc in blink::`anonymous namespace'::CreateContextProviderOnMainThread | $8,000 | 2023-01-25 |
1376067 | Heap-buffer-overflow in blink::CSSParserImpl::ConsumeStyleRule | - | 2023-01-25 |
1355718 | Security: UAF in hci_cmd_timeout | $15,000 | 2023-01-24 |
1367547 | Security: Heap-use-after-free in autofill::AutofillContextMenuManager::ExecuteCommand | $5,000 | 2023-01-24 |
1370393 | Container-overflow in ui::Layer::OnDeviceScaleFactorChanged | - | 2023-01-24 |
1374341 | Heap-buffer-overflow in blink::GetCrossOriginAttributeValue | - | 2023-01-24 |
1375932 | DCHECK failure in isolate->context().is_null() || isolate->context().IsContext() in runtime-string | - | 2023-01-24 |
1376069 | Crash in v8::internal::Runtime_StringCharCodeAt | - | 2023-01-24 |
1370502 | Security: Double free in setup_cb_free | - | 2023-01-23 |
1372665 | Security: UAF in MyFilesSizeCalculator::ComputeLocalFilesSize, | - | 2023-01-23 |
1372695 | Security: heap-use-after-free third_party\blink\renderer\core\workers\worker_thread.cc:905 in blink::WorkerThread::PauseOrFreezeOnWorkerThread | $7,000 | 2023-01-23 |
1329374 | Security: heap-buffer-overflow on ash/shelf/shelf_view.cc (chromeOS) | - | 2023-01-21 |
1368587 | Security: heap-use-after-free on aura::WindowOcclusionTracker::MaybeObserveAnimatedWindow | $1,000 | 2023-01-21 |
1374226 | Illegal-instruction in blink::NGTableSectionLayoutAlgorithm::Layout | - | 2023-01-21 |
1374535 | DCHECK failure in imm.index < num_locals() in function-body-decoder-impl.h | - | 2023-01-21 |
1374626 | DCHECK failure in JSFunction::cast(entry.map(isolate).GetConstructor()) == native_context.array_fu | - | 2023-01-21 |
1372999 | Security: Heap-use-after-free in SpeechRecognitionRecognizerImpl::ChangeLanguage | $10,000 | 2023-01-19 |
1373314 | Security: WebGPU: Out of bounds write in OnBufferMapAsyncCallback | - | 2023-01-19 |
1374232 | v8_regexp_parser_fuzzer: DCHECK failure in index <= known_captures in regexp-parser.cc | - | 2023-01-19 |
1344647 | chrome.debugger API bypasses the runtime_blocked_hosts cookie protection | $3,000 | 2023-01-18 |
1354518 | Security: .url files can be saved via getFileHandle and redirect showSaveFilePicker to arbitrary file | $1,000 | 2023-01-18 |
1366330 | CrOS: Vulnerability reported in media-libs/tiff | - | 2023-01-18 |
1371860 | Security: UAF in mojo::SimpleWatcher::Context in MojoIpcz feature (browser process) | $20,000 | 2023-01-18 |
1371926 | Security: file_type_policies changes reintroduce attack surface | - | 2023-01-18 |
1372500 | CHECK failure: !v8::internal::FLAG_enable_slow_asserts || (IsJSReceiver_NonInline(*this)) in js | - | 2023-01-18 |
1372653 | Use-after-poison in blink::NGBlockNode::StoreResultInLayoutBox | - | 2023-01-18 |
1372784 | use after poison in HeapObjectHeader::LoadEncoded() | $10,000 | 2023-01-18 |
1373770 | DCHECK failure in gc_epilogue_callbacks_.IsEmpty() in local-heap.cc | - | 2023-01-18 |
1373772 | CHECK failure: diff <= 0.5 | - | 2023-01-18 |
1080624 | CrOS: Vulnerability reported in sys-libs/glibc | - | 2023-01-16 |
1162252 | CrOS: Vulnerability reported in x11-libs/gdk-pixbuf | - | 2023-01-16 |
1176031 | Reading local files through an extension that only has the "downloads" permission | $5,000 | 2023-01-16 |
1294202 | CrOS: Vulnerability reported in dev-libs/protobuf | - | 2023-01-16 |
1298886 | CrOS: Vulnerability reported in media-libs/tiff | - | 2023-01-16 |
1354271 | Security: [ANGLE] Heap-buffer-overflow caused by writing exceeding the querypool size | $17,000 | 2023-01-14 |
1365004 | Security: Chrome Android: Incognito Mode grants access to the address bar although reauthentication is required | - | 2023-01-14 |
1279268 | Security: Page can cause autofill prompt to render near cursor in order to bypass intentional mouse movement input requirements for autofill (Bypass of issue 1240472 fix) | $3,000 | 2023-01-13 |
1356211 | Security: XML object's heap memory difference leaking or potential ASLR bypass in libXML | $1,000 | 2023-01-13 |
1365330 | Security: heap-use-after-free in blink::LocalFrameView::PerformLayout (incomplete fix for CVE-2022-3199) | - | 2023-01-12 |
1366415 | UAF in AccessibilityManager | $2,000 | 2023-01-12 |
1369871 | Security: Race condition in JSCreateLowering, leading to RCE | $20,000 | 2023-01-12 |
1369882 | Security: use-after-poison interface_endpoint_client.cc:900 in mojo::InterfaceEndpointClient::HandleValidatedMessage | $10,000 | 2023-01-12 |
1370439 | UAF in SelectFileDialogLinuxKde::CallKDialogOutput | $7,000 | 2023-01-12 |
1370969 | Crash in blink::NGBlockNode::StoreResultInLayoutBox | - | 2023-01-12 |
1350442 | Security: UAF in BackForwardCache | $30,000 | 2023-01-11 |
1358168 | Security: clang-analyzer-core.uninitialized.Assign in third_party/ffmpeg/libavformat/riffdec.c | - | 2023-01-11 |
1364662 | Security: UAF in in safe_browsing::IncidentReportingService::AddIncident(browser process) | $7,000 | 2023-01-11 |
1367650 | DCHECK failure in offsets.size() != 0 in maglev-graph-builder.cc | - | 2023-01-11 |
1370416 | DCHECK failure in is_loadable() in maglev-ir.h | - | 2023-01-11 |
1370423 | DCHECK failure in HAS_SMI_TAG(ptr) in smi.h | - | 2023-01-11 |
587956 | Security: Android: Apps with external storage access can steal CSRF tokens | - | 2023-01-10 |
1361612 | heap-use-after-free : webrtc::`anonymous namespace'::ProduceRemoteInboundRtpStreamStatsFromReportBlockData | - | 2023-01-10 |
1363583 | Security: Heap-use-after-free in UserNoteService::OnNoteCreationDone | $5,000 | 2023-01-10 |
1366843 | uaf in v8_inspector::InjectedScript::addPromiseCallback | $1,000 | 2023-01-10 |
1367862 | DCHECK failure in IsPrimitiveMap() in map-inl.h | - | 2023-01-10 |
1368046 | Security: Type confusion in V8 | $10,000 | 2023-01-10 |
1370400 | DCHECK failure in key->IsJSReceiver() in runtime-collections.cc | - | 2023-01-10 |
1370402 | DCHECK failure in target().IsUndefined() || target().IsJSReceiver() in js-weak-refs-inl.h | - | 2023-01-10 |
1259492 | Security UI Spoofing on Chrome for Android due to the Contact permission dialog hiding the fullscreen alert message | $7,500 | 2023-01-09 |
1363287 | DCHECK failure in GetCurrentStackPosition() >= stack_guard()->real_climit() - 32 * KB in isolate.c | - | 2023-01-08 |
1368076 | Security: Report 2 Vulnerabilities in WebSQL | $13,000 | 2023-01-07 |
1051198 | Compromised renderer can arbitrarily read the clipboard | - | 2023-01-06 |
1363040 | uaf in PermissionStatus::OnPermissionStatusChange | $2,500 | 2023-01-06 |
1366812 | Security: UAF in content::DevToolsSession::DispatchProtocolResponse (browser process) | $1,000 | 2023-01-06 |
1366464 | Back Forward Cache storage of RenderViewHost is unsafe | - | 2023-01-05 |
1367680 | GPU failure in blink::NGPhysicalBoxFragment::CheckSameForSimplifiedLayout | - | 2023-01-05 |
1355560 | heap-use-after-free ui/views/view.cc:1898:7 in views::View::HandleAccessibleAction | $2,000 | 2023-01-04 |
1366806 | Security: Heap-use-after-free in InstallablePaymentAppCrawler::OnPaymentMethodManifestParsed | $38,000 | 2023-01-04 |
1367678 | DCHECK failure in generator_block->control_node()->opcode() == Opcode::kSwitch in maglev-regalloc. | - | 2023-01-04 |
345205 | DevTools: Combat self-xss | - | 2023-01-04 |
1360042 | V8: Generic lowering of JSForInPrepare tries to read from FixedArray | - | 2023-01-03 |
1363030 | uaf in ArcInputOverlayManager::ReadData | - | 2023-01-03 |
1364604 | Security: heap-use-after-free in GrClientMappedBufferManager::owningDirectContext | $15,000 | 2023-01-03 |
1367231 | Security: UAF in AutofillContextMenuManager::ExecuteCommand | $7,000 | 2023-01-03 |
1367651 | CHECK failure: size <= kMaxRegularHeapObjectSize | - | 2023-01-03 |
1367993 | Security: WebRTC crash in `AudioMultiVector::PushBackInterleaved` | - | 2023-01-03 |
1340879 | Security: Custom Tab HTTP Header Injection | $3,000 | 2023-01-02 |