beidson

WebKit security specialist

83 commits (11mo)
14 security fixes
5 hardening
View all commits on GitHub ↗

Summary

beidson works primarily in the WebKit process-model layer — site isolation, UI/Network process IPC, and the WKWebView API surface that straddles them — with WebCore changes tracking those same paths. The security work clusters tightly around message checks against a compromised WebContent process: back/forward list file-URL spoofing, MessagePort ownership confusion involving the Network Process, and cross-origin spoofs through BroadcastChannel and the app badge API; one recent fix is an explicit incomplete-fix follow-up to an earlier back/forward list message check, and several site-isolation commits correct page/frame identifier confusion in URL scheme handlers, user style sheets, and web extension plumbing. Systematic-variant candidate: IPC entry points that trust process-supplied identifiers — back/forward item IDs, MessagePort handles, page and frame identifiers under site isolation — since that exact shape recurs across both the security and the non-security commits here.

Components

WebKit
64%
WebCore
21%
Platform
5%
Other
5%
WTF
3%
WebInspector
1%

Security Fix History

1 / 2

Hardening Commits

Recent Commits

1 / 6

← All Contributors