Chromium issue trackers document several security flaws affecting browser components including media parsing, graphics handling, extensions, and developer tooling. Reported issues include missing range validation for second_chroma_qp_index_offset in the H.264 PPS parser (h264_parser.cc), which could allow out-of-spec values to reach kernel GPU drivers; an out-of-bounds memory access in WebGL texImage2D tied to UNPACK_IMAGE_HEIGHT; and a use-after-free in V8ConsoleAgentImpl::reportAllMessages. A separate Chromium bug also references a security vulnerability in WebP, underscoring continued exposure in image and media processing paths.
The reports also describe a privacy weakness in which browser extensions could infer full tab URLs through a side-channel involving declarativeNetRequest. Taken together, the disclosed bugs span memory corruption, insufficient input validation, and information leakage across high-risk surfaces commonly reachable through web content, browser extensions, and rendered media, with potential downstream impact that includes browser compromise, data exposure, or interaction with lower-level GPU driver code.

See affected versions and whether adversaries are exploiting it.
15 events from the most recent confirmed update back to the earliest known activity.
A Chromium issue was published describing an integer overflow in WebGPU (Dawn/Tint Metal) SubstituteOverrides that can cause threadgroup out-of-bounds read and write. The reference provides no additional details on exploitation, patching, or impact beyond the issue title.
A Chromium issue was published reporting a use-after-free in V8ConsoleAgentImpl::reportAllMessages. The reference contains no further information about fixes, impact, or exploitation.
A Chromium issue was published describing a time-of-check/time-of-use flaw in NdkVideoEncodeAccelerator where shared memory is re-read after write, allowing attacker-controlled bitstream parsing. The reference provides no additional details on exploitation, patching, or impact beyond the issue title.
A Chromium issue was published describing missing range validation on second_chroma_qp_index_offset in the H.264 PPS parser, allowing out-of-spec values to reach kernel GPU drivers. No patch or exploitation details are provided in the reference.
A Chromium issue was published reporting that extensions can leak full tab URLs through declarativeNetRequest via a side-channel attack. The reference does not include mitigation or disclosure details beyond the issue title.
A Chromium issue was published describing an out-of-bounds memory access in WebGL texImage2D involving UNPACK_IMAGE_HEIGHT. No additional exploit, patch, or impact details are included in the reference.
A Chromium issue was published alleging that extensions can hijack Gemini in the browser webview process by abusing declarativeNetRequest permissions. The issue says this could enable prompt theft, PII leakage, and unrestricted camera and microphone access.
A Chromium issue was published concerning prerendering of cross-origin iframes. The reference provides no synopsis, patch, exploitation details, or further technical context beyond the issue title and ID 440387014.
A Chromium issue was published describing a MiraclePtr bypass caused by PtrCount overflow. The reference provides no synopsis, patch, or exploitation details beyond the issue title.
A Chromium security issue tracking a vulnerability in WebP was published as crbug 1479274. The reference provides no further technical details or remediation information.
A new Chromium issue, 500091052, is referenced by the source. No synopsis, technical details, remediation information, or publication date are provided in the reference.
A new Chromium issue, 480993682, is referenced by the source. No synopsis, technical details, remediation information, or publication date are provided in the reference.
A new Chromium issue, 486906037, is referenced by the source. No synopsis, technical details, remediation information, or publication date are provided in the reference.
A new Chromium issue, 486079015, is referenced by the source. No synopsis, technical details, remediation information, or publication date are provided in the reference.
A new Chromium issue, 485115554, is referenced by the source. No synopsis, technical details, remediation information, or publication date are provided in the reference.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
15 references tracked. Mallory keeps watching after this page renders.
issues.chromium.org
Open sourceissues.chromium.org
Open sourceissues.chromium.org
Open sourceissues.chromium.org
Open sourceissues.chromium.org
Open sourceissues.chromium.org
Open sourceissues.chromium.org
Open sourceissues.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.