Reports
Weekly WebKit security reports. Filtered by IntegerOverflow.
-
W31
8 picks from 470 commits 2026-08-01 – 07 1 security 7 dev v1.3.0
Three WebAuthn replies came back on a queue WebKit didn't choose.; Two array opcodes shared one case label in JSC's write-barrier phase.; The memory64 check that only looked at the memory it was holding.
IntegerOverflow3UAF2Race1TypeConfusion1+1 -
W26
8 picks from 557 commits 2026-06-27 – 07-03 6 security 2 dev v1.7.0
Omit one argument and the promise-pair bindings hand you an exception cell.; A buffer you can free between assigning it and pressing play.; A compromised renderer names a file it can't read, and Safari hands it back.
UAF40Race20AuthBypass16LogicError15+55 -
W24
7 picks from 397 commits 2026-06-13 – 19 6 security 1 dev v1.3.3
Two of four sibling access types never told the collector what they held.; The literal parser knew __proto__ could run script, and guarded the wrong thing.; The dialog handed back a return value from memory the page just freed.
UAF6Race5TypeConfusion3AuthBypass3+7 -
W23
8 picks from 484 commits 2026-06-06 – 12 6 security 2 dev v1.3.3
Closing a page freed the <html> element out from under its own shadow trees.; A scope guard that pinned the string cell but not the bytes you were reading; Streams' pipeTo checked for a fake promise with a cast that never fails
UAF9OOB5Race5CrossOrigin4+13 -
W22
9 picks from 480 commits 2026-05-30 – 06-05 6 security 3 dev v1.3.3
The CORS policy took a detour through the process it was written to contain.; The eval cache kept a raw pointer that nothing was keeping alive.; The array that came back from an OSR exit disagreed with itself about its layout.
CrossOrigin6Other5UAF4LogicError3+10 -
W21
6 picks from 423 commits 2026-05-23 – 29 6 security v1.3.3
B3 was right that the value was dead — the collector agreed, and freed it.; The DFG certified a property absent from an object that owned it outright.; An IC exit undid a stack adjustment that had never happened.
UAF10OOB5AuthBypass5LogicError5+17