beidson
WebKit security specialist
Summary
beidson works primarily in the WebKit process-model layer — site isolation, UI/Network process IPC, and the WKWebView API surface that straddles them — with WebCore changes tracking those same paths. The security work clusters tightly around message checks against a compromised WebContent process: back/forward list file-URL spoofing, MessagePort ownership confusion involving the Network Process, and cross-origin spoofs through BroadcastChannel and the app badge API; one recent fix is an explicit incomplete-fix follow-up to an earlier back/forward list message check, and several site-isolation commits correct page/frame identifier confusion in URL scheme handlers, user style sheets, and web extension plumbing. Systematic-variant candidate: IPC entry points that trust process-supplied identifiers — back/forward item IDs, MessagePort handles, page and frame identifiers under site isolation — since that exact shape recurs across both the security and the non-security commits here.
Components
Security Fix History
- 2026-09-08 Incomplete fix of WebKit bug 315528 (Message check file urls in back/forward list messages) 2026-W36
- 2026-09-04 WKWebView does not enforce CORS response header validation for apps' custom schemes after registerURLSchemeAsCORSEnabled 2026-W35
- 2026-08-26 BroadcastChannel cross-origin spoof ·
- 2026-07-02 Guard against MessagePort confusion in the Network Process ·
- 2026-07-02 Compromised WebContent process can gain arbitrary file URL access by spoofing back/forward list messages ·
- 2026-07-01 Build fix after 249edf86a9f55 ·
- 2026-06-30 Need a process-specific `WebBackForwardListItem::allItems()` instead of the process-global map for better message checki ·
- 2026-06-08 Cross origin iframes should not be able to set the app badge. ·
- 2026-06-04 MessagePorts a WebContent process already has should be invalidated if the Networking process disconnects ·
- 2026-06-03 rdar://172395438 2026-W22
Hardening Commits
- 2026-09-08 Incomplete fix of WebKit bug 315528 (Message check file urls in back/forward list messages) 2026-W36
- 2026-07-07 Null check pageClient() inside WebPageProxy::didAttachToRunningProcess
- 2026-07-02 Guard against MessagePort confusion in the Network Process ·
- 2026-06-08 Cross origin iframes should not be able to set the app badge. ·
- 2026-06-03 rdar://172395438 2026-W22
Recent Commits
- 2026-09-08 (305413.959@safari-7624-branch) Embedded image is not load as image in mail app
- 2026-09-08 Incomplete fix of WebKit bug 315528 (Message check file urls in back/forward list messages) 2026-W36
- 2026-09-04 WKWebView does not enforce CORS response header validation for apps' custom schemes after registerURLSchemeAsCORSEnabled 2026-W35
- 2026-09-03 Update test expectations for two EnhancedSecurity API tests
- 2026-08-26 BroadcastChannel cross-origin spoof ·
- 2026-08-18 [Site Isolation] Some WKWebView-level APIs don't message all processes associated with the page
- 2026-08-17 [Site Isolation] Web inspector extension panels cannot find the inspected tab
- 2026-08-16 [Site Isolation] Web extension page identifiers are built for the wrong process
- 2026-08-15 [Site Isolation] Fix page identifier confusion in _WKUserStyleSheet code
- 2026-08-12 MessagePorts + SharedWorkers have a bad time with recently added message checks
- 2026-08-06 [Site Isolation] Some website policies applied to main frame navigations don't apply to cross site iframes
- 2026-08-05 Excessive CoreIPCNSURLRequest logging from CoreMedia generated NSURLRequests
- 2026-08-01 (Site isolation) Fix WKURLSchemeHandler process confusion
- 2026-07-29 Queue multiple JS dialog requests in the UI process (possible with site isolation enabled)
- 2026-07-28 Add tests verifying cross-origin iframe window.alert() behavior