graouts

WebCore security specialist

186 commits (11mo)
7 security fixes
1 hardening
View all commits on GitHub ↗

Summary

graouts works almost exclusively in WebCore's animation stack — Web Animations, scroll-driven timelines, threaded/accelerated animations, and `animation-trigger` property parsing — with recent output concentrated on `timeline-scope` resolution and style-originated timeline matching. The security fixes are not scattered across that surface: they cluster in accelerated and threaded animation paths, covering a cross-thread UAF reachable in the UIProcess through an unguarded static `TinyLRUCache`, a use-after-free from `m_timelines` rehashing inside `AnimationTimelinesController::suspendAnimations`, and repeated crashes from accelerated animations that combine view-progress timeline ranges with a scroll time — with the `OrderedHashSet` adoption for `AnimationCollection` targeting the same container-mutation-during-iteration class. Systematic-variant candidate: object lifetime and iteration safety in animation state shared across the WebProcess/UIProcess boundary, plus the timeline-matching code, which is being actively rewritten rather than maintained.

Components

WebCore
77%
WebKit
10%
WTF
9%
Platform
2%
Other
1%
WebGPU
1%

Security Fix History

Hardening Commits

Recent Commits

1 / 13

← All Contributors