Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Showing 1000 of 9099 matching CPE(s) for the range"

Yes it seems to go back to Chrome version 9 lol

uhoh



Impacted versions in CVE listings are normally not validated.

For example, my CVE-2022-2007 in WebGPU also supposedly goes back to Chrome version 9. That's impossible, as WebGPU wasn't even a concept back then.

https://nvd.nist.gov/vuln/detail/CVE-2022-2007

It's relatively easy to find the offending commit by creating a unit test and using git bisect. I usually don't do it for public Chromium bug reports since it's extra work and $0 in extra rewards.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: