qualitylab

the station

Chromium: memory safety

tier II/2024/chromium.org security documentation

https://www.chromium.org/Home/chromium-security/memory-safety/

Method

"mistakes with C/C++ pointers"

Population

"Analysis based on 912 high or critical severity security bugs since 2015, affecting the Stable channel."

What it does not show

Restricted to high and critical severity bugs on one release channel — nothing about medium or low severity, or pre-release channels. A descriptive proportion of a fixed historical population with no causal analysis and no breakdown by new versus legacy code.

The Chromium Project

Around 70% of high and critical severity security bugs are memory-unsafety problems, and about half of those are use-after-free.

Tier II: Observational analysis of one project’s own severe-bug record over nine years with a stated population. No comparison group.

Cited by