b-weinstein
WebKit contributor
Summary
Works exclusively on WebKit's Web Extensions layer, with recent commits forming a single tight cluster around implementing the `browser.offscreen` extension API — offscreen web view lifecycle management, feature-flag gating, and API surface restriction. The pattern is new-feature implementation rather than security or hardening work, though the commits themselves are about boundary decisions: limiting the offscreen view to `browser.runtime` only, and placing it in a window so audio playback works. Newly landed extension API surfaces gated behind a flag are a reasonable place to check whether the runtime-only restriction holds in practice and whether the windowed offscreen view leaks capabilities beyond audio.
Components
WebKit
73%
WebCore
13%
WTF
7%
Platform
7%
Security Fix History
- 2026-08-28 Enable the offscreen web extension API 2026-W34
Hardening Commits
Recent Commits
- 2026-08-31 Extension service worker loses clients when it is unloaded and reloaded
- 2026-08-28 Enable the offscreen web extension API 2026-W34
- 2026-08-28 Fix compilation issue with WK_WEB_EXTENSIONS_OFFSCREEN on iOS
- 2026-08-26 browser.offscreen shouldn't be available to offscreen pages
- 2026-08-26 Extension background service worker can't find other extension pages using clients.matchAll
- 2026-08-18 Protect dynamic web extension properties from a null page
- 2026-08-14 Only expose the offscreen API if the feature flag is on
- 2026-08-14 Put the extension created offscreen web view into a window so it's able to play audio
- 2026-08-13 Only give the offscreen web view access to the browser.runtime API
- 2026-08-11 Manage an offscreen web view when implementing the browser.offscreen extension API
- 2026-08-08 Web Extensions: Add support for the offscreen API