All findings

CVE-2026-16420, CVE-2026-16421, CVE-2026-19168 high

Chrome directly credits XBOW on three WebAudio and V8 CVEs

Chrome's July and August releases directly credit XBOW on three high-severity browser vulnerabilities.

Bug class
WebAudio type confusion and implementation flaws plus V8 memory safety
Affected codebase
Chromium WebAudio and V8
Credited system
XBOW
Disclosed
August 6, 2026
Attribution
Direct source attribution
Severity
high
Source status: Chrome directly says CVE-2026-16420 and CVE-2026-16421 were found by XBOW and credits XBOW on CVE-2026-19168. Adjacent Google-found release CVEs are excluded.

Summary

The July release contains two direct XBOW WebAudio credits. The August release adds one direct XBOW V8 credit. Only those three rows are included; six nearby July rows and six nearby August rows attributed to Google or other researchers are not assigned to XBOW.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.