Root cause
Control-flow analysis treated an initialization safety check as redundant without preserving its guarantee across every incoming path.
Demonstrated impact
The report demonstrated sandboxed renderer memory corruption. A sandbox escape or full-machine compromise is not established.
Lessons for review
- Check-removal optimizations must preserve initialization guarantees across all control-flow paths.
- Separate a compiler fix, stable-release availability and public report access in remediation records.
Award and evidence
Panel decision and tracker reward metadata identify one report. Dollar notation uses official Chromium USD context. Cash receipt is unverified.
Read the public rendered Chromium issue and official release; cross-checked panel decision, reward metadata and distinct CVE.
- Payment completion is unverified; USD relies on official program context.
- Issue dates follow displayed calendar dates; timestamp timezone was not established.
- Release page was corrected November 17 to add other CVEs. This entry remains in the original main list.
Recorded timeline
- Published
- 2026-01-22explicit · Comment #24 records removal of issue access restrictions.
- Public Disclosure
- 2025-10-28explicit · Vendor advisory preceded full issue access.
- Reported
- 2025-10-10explicit
- Awarded
- 2025-10-17explicit
- Fixed
- 2025-10-28explicit · Stable release announced staged rollout; main fix recorded October 10 and Fixed status October 15.
- Award Announced
- 2025-10-28explicit · Listed in the dated release notice; no original-page snapshot reviewed.
Sources and provenance
- Chromium issue 450618029 Google Chromium security team · reviewed 2026-10-02
- Chrome Stable Channel Update for Desktop, 2025-10-28 Google Chrome team · reviewed 2026-10-02
- Security rewards at Google: Two MEEELLION Dollars Later Chromium team · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.