kmonsen

WebCore security specialist

31 commits (10mo)
7 security fixes
5 hardening
View all commits on GitHub ↗

Summary

kmonsen works primarily in WebCore and the WebKit process layer, and the commit stream is dominated by crashes reachable from malformed cross-process input: null URLs and schemes in blob-registry and CORS-scheme IPC, unvalidated enum decoding in WebProcessPool messages, overlong WebRTC hostnames, and non-finite geometry reaching CALayer in the GPU process. A second cluster covers layout and rendering edge cases — anchor positioning resolving against a `<br>`, sticky positioning under `-webkit-box-reflect`, `::picker-icon` attached to a non-renderer target, `getEnclosureList()` over a `display:contents` `<g>` — mostly assertion failures and null-deref rather than memory corruption, with the security-tagged work leaning toward lifetime and iterator-invalidation issues (WeakHashSet iteration, destroyed-object checks, DeferredPromise double-consuming a pending exception). Systematic-variant candidate: the `CoreIPC*` conversion helpers. `CoreIPCSecTrust::createSecTrust()` inserting nil into an `NSMutableDictionary` for empty `CoreIPCData` and `CoreIPCCGColorSpace::toCF()` dereferencing a null `Box<>` are the same bug class on different types, so the remaining CoreIPC converters are worth sweeping for empty/null payload handling from a compromised WebContent process.

Components

WebCore
42%
WebKit
31%
Platform
11%
WTF
8%
WebGPU
6%
Platform Cocoa
3%

Security Fix History

Hardening Commits

Recent Commits

1 / 3

← All Contributors