Project Zero Bugs@ProjectZeroBugs·1dA 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens projectzero.google/2026/05/pixel-…Çevir English378380128.1K179
Project Zero Bugs@ProjectZeroBugs·16 NisV8 Sandbox Bypass: Memory corruption during BigInt division project-zero.issues.chromium.org/issues/4788143…Çevir English099247.4K43
Project Zero Bugs@ProjectZeroBugs·9 NisAdobe DNG SDK: integer overflow in dng_pixel_buffer::OptimizeOrder leads to out-of-bounds memory access project-zero.issues.chromium.org/issues/4782129…Çevir English03143.7K7
Project Zero Bugs@ProjectZeroBugs·9 NisAdobe DNG SDK: out-of-bounds write in dng_render_task::ProcessArea due to coordinate system confusion project-zero.issues.chromium.org/issues/4791113…Çevir English02115.1K8
Project Zero Bugs@ProjectZeroBugs·6 NisWindows: WinLogon WlAccessabilitypDeleteSATKey Registry Deletion EoP project-zero.issues.chromium.org/issues/4663005…Çevir English03123.9K6
Project Zero Bugs@ProjectZeroBugs·6 NisWindows: ATBroker CopySettingsToLockedDesktop Information Disclosure project-zero.issues.chromium.org/issues/4663015…Çevir English0293.2K4
Project Zero Bugs@ProjectZeroBugs·6 NisWindows: OSK Shared Session Key EoP project-zero.issues.chromium.org/issues/4663034…Çevir English05273.9K10
Project Zero Bugs@ProjectZeroBugs·2 Nisvpu driver allocation and free of dmabuf and iova can race causing UAF read project-zero.issues.chromium.org/issues/4658246…Çevir English13394.6K18
Project Zero Bugs@ProjectZeroBugs·26 MarV8 Sandbox Bypass: Memory corruption during StringToBigInt conversion project-zero.issues.chromium.org/issues/4740358…Çevir English06424.5K24
Project Zero Bugs@ProjectZeroBugs·26 MarV8 Sandbox Bypass: Arbitrary bytecode execution due to BytecodeArray swapping before code deoptimization project-zero.issues.chromium.org/issues/4743109…Çevir English05414.3K26
Project Zero Bugs@ProjectZeroBugs·25 Marvpu driver open and close instance ioctls race causing UAF project-zero.issues.chromium.org/issues/4636725…Çevir English08415.3K21
Project Zero Bugs@ProjectZeroBugs·12 MarLibjxl: Integer overflow in pixel buffer size calculation may lead to memory corruption project-zero.issues.chromium.org/issues/4653777…Çevir English04344.8K19
Project Zero Bugs@ProjectZeroBugs·9 Marvpu driver mmap allows OOB physical mappings project-zero.issues.chromium.org/issues/4634382…Çevir English06475.6K23
Project Zero Bugs@ProjectZeroBugs·5 MarOn the Effectiveness of Mutational Grammar Fuzzing projectzero.google/2026/03/mutati…Çevir English07665.4K55
Project Zero Bugs@ProjectZeroBugs·3 MarAndroid: shell->system_server LPE via unbounded recursion and missing stack probes project-zero.issues.chromium.org/issues/4658279…Çevir English019877.6K39
Project Zero Bugs@ProjectZeroBugs·2 MarAdobe DNG SDK: multiple integer arithmetic issues in embedded JXL image support project-zero.issues.chromium.org/issues/4633351…Çevir English0384K3
Project Zero Bugs@ProjectZeroBugs·2 MarAdobe DNG SDK: missing allocation check leads to an arbitrary memory write in JXL format processing project-zero.issues.chromium.org/issues/4642507…Çevir English08335.2K13
Project Zero Bugs@ProjectZeroBugs·2 MarAdobe DNG SDK: integer overflow in dng_ref_counted_block::Allocate leads to memory corruption on 32-bit platforms project-zero.issues.chromium.org/issues/4679416…Çevir English04144K8
Project Zero Bugs@ProjectZeroBugs·12 ŞubBypassing Administrator Protection by Abusing UI Access projectzero.google/2026/02/window…Çevir English510374.6K18
Project Zero Bugs@ProjectZeroBugs·9 ŞubSamsung: libimagecodec.quram.so DNG out-of-bounds read in DoCopyArea16_R32 during the Render phase project-zero.issues.chromium.org/issues/4574014…Çevir English08576.6K22