Chromium issue trackers show two distinct browser security defects affecting separate components: a regular expression denial-of-service condition in DevTools and a heap-use-after-free bug in Blink's FontFeatureValuesMapIterationSource::FetchNextItem. The DevTools issue indicates a flaw that could allow specially crafted input to trigger excessive regular-expression processing and degrade browser responsiveness, while the Blink report points to a memory-safety error in font feature value iteration that can lead to unstable behavior and potential exploitation.
The reports highlight risk across both developer tooling and the rendering engine, with the Blink flaw standing out because use-after-free vulnerabilities in browser code are commonly scrutinized for possible code-execution impact. Although the available tracker entries provide limited public detail, the combination of a denial-of-service bug and a memory-corruption issue underscores ongoing exposure in Chromium components that are widely inherited by downstream browsers and applications.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A Chromium issue was published for a heap-use-after-free in blink::FontFeatureValuesMapIterationSource::FetchNextItem. The reference does not include further details on exploitation, impact, or a fix.
A Chromium issue tracking a Regular Expression Denial of Service vulnerability in DevTools was published. No additional technical details or remediation information are provided in the reference.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.