charliewolfe

WebCore security specialist

162 commits (9mo)
17 security fixes
8 hardening
View all commits on GitHub ↗

Summary

Works primarily in WebCore and the WebKit process layer, concentrated on the network process: cookies, ITP and storage access, NetworkStorageSession, and the IPC surface between the web and networking processes. Nearly all of the security work sits on that boundary — IPC message validation plus scheme/cookie access checks on loaders like LoadImageForDecoding, removal of over-broad allowances such as the blanket storage-root file path exemption in blob enforcement, and dropping attacker-influenced fields (treatAsSameOriginNavigation) from NavigationActionData entirely. A parallel thread of non-flagged commits corrects process-model scoping — network-process state re-keyed from PageIdentifier to WebPageProxyIdentifier, Apple Pay's canMakePayments cache moved from per-page to per-WebProcess — the same class of mistake that leaks state across origins under site isolation. Systematic-variant candidate: the ITP/storage-access IPC set has been swept more than once months apart, so unvalidated siblings in NetworkConnectionToWebProcess and any remaining network-process state still keyed per-page are the natural next targets.

Components

WebCore
48%
WebKit
39%
Platform
6%
Other
2%
WebGPU
2%
JSC
1%

Security Fix History

1 / 2

Hardening Commits

Recent Commits

1 / 11

← All Contributors