Root cause
The graphics translation layer insufficiently validated untrusted input.
Demonstrated impact
Insufficiently validated graphics input could cross a browser security boundary; the vendor classified the issue High.
Lessons for review
- Validate untrusted graphics inputs at security boundaries and verify that mitigations cover all relevant input paths.
- Distinguish issue-status fixes from stable-release availability.
Award and evidence
USD 25,000 on June 4 plus USD 225,000 on June 29 for one report. Case notices use $; USD is contextual from the official Chromium program source. No currency conversion or cash-receipt claim.
Public Chromium issue award/date metadata read in the cloud browser; official release corroborates exact per-issue total and CVE. No operational details retained.
- Case notices use dollar notation; USD denomination relies on official Chromium program context.
- Award decisions are established; payment completion is not.
- Fixed status and publicly available stable release are separate dates.
- Release credits an anonymous researcher. No identity or per-person split is inferred.
Recorded timeline
- Published
- 2026-09-03explicit · Full report access restrictions removed; vendor release notice appeared earlier.
- Public Disclosure
- 2026-06-30explicit · Vendor release disclosure; full issue access was enabled later.
- Reported
- 2026-03-13explicit
- Awarded
- 2026-06-29explicit
- Fixed
- 2026-06-30explicit · Documented stable release; issue was marked Fixed 2026-05-27. Backport availability may differ.
- Award Announced
- 2026-06-30explicit · Per-issue reward listed in the public release notice.
Sources and provenance
- Chromium issue 492218546 Google Chromium security team · reviewed 2026-10-02
- Chrome Stable Channel Update for Desktop, 2026-06-30 Google Chrome team · reviewed 2026-10-02
- Security rewards at Google: Two MEEELLION Dollars Later Chromium team · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.