Matthew Finkel (unlinked)
WebKit security specialist
Summary
Finkel works the Cocoa networking layer — cookie policy (partitioned cookies, SameSite handling), WebSocket and WebTransport connection setup, and Private Click Measurement proxying — spread across WebKit, Platform, and WebCore, with the remainder going to test re-enablement and site-specific quirks. The security fixes are almost all one bug class: a privacy or cookie-policy attribute that the primary resource-load path sets correctly but an alternate transport or unusual document origin fails to propagate — SameSite Strict/Lax bypassed for srcdoc iframes, partitioned-cookie flags missing on WebSocket requests, WebTransport connections left unmarked, PCM traffic escaping the proxy. Systematic-variant candidate: enumerate every code path in the Cocoa stack that constructs a network connection and check whether it carries the partitioning, SameSite, and proxy attributes the document loader applies.
Components
Security Fix History
- 2026-09-14 [cocoa] WebTransport is not marking connections ·
- 2026-08-21 Srcdoc iframes bypass SameSite Strict and Lax cookies 2026-W33 CVE-2026-64728
- 2026-07-01 [cocoa] _setAllowOnlyPartitionedCookies may not be set on WebSocket requests · CVE-2026-43708
- 2026-06-05 [PCM] Support proxying PCM requests on iOS ·
- 2026-03-21 [PCM] Connections for Private Click Measurement are not proxied
Hardening Commits
- No hardening commits recorded
Recent Commits
- 2026-09-14 [cocoa] WebTransport is not marking connections ·
- 2026-08-21 Srcdoc iframes bypass SameSite Strict and Lax cookies 2026-W33 CVE-2026-64728
- 2026-07-16 [cocoa] multiple-cookies partitioned cookies test is a constant failure
- 2026-07-10 Re-enabled WebSocket cookie tests
- 2026-07-01 [cocoa] Add MiniBrowser setting for allowing all TLS certificates
- 2026-07-01 [cocoa] _setAllowOnlyPartitionedCookies may not be set on WebSocket requests · CVE-2026-43708
- 2026-06-23 [cocoa] Allow udp in adattributiond sandbox
- 2026-06-11 [cocoa] Enable partitioned cookie and tests on 26.2+
- 2026-06-11 Partitioned cookies may not be sent on resource requests
- 2026-06-10 Add quirk on battle.net for login accessing loopback
- 2026-06-05 [PCM] Support proxying PCM requests on iOS ·
- 2026-06-04 "Non-secure site connections" error page blocks localhost with no option to proceed
- 2026-04-29 [cocoa] Explicitly handle cookies with NSHTTPCookieSameSiteNone
- 2026-04-22 Add quirk on Google ccTLD for changing profile pic
- 2026-03-21 [PCM] Connections for Private Click Measurement are not proxied