
$250,000 bounty for CVE-2026-9876, reported by happy2me. Critical WebGL UAF in Chrome. Chromium’s issue title links it to a bypass of the previously exploited Qualcomm Adreno CVE-2025-27038. happy2me must be very happy today 😄 https://issues.chromium.org/issues/493747593 https://t.co/8TvAQjD4Rz
Post summary
A $250K bounty is announced for the newly disclosed CVE‑2026‑9876, a critical WebGL use‑after‑free vulnerability in Chrome linked to a Qualcomm Adreno bypass.


