pascoej
Platform security specialist
Summary
pascoej works primarily on WebKit's credential and identity surface — WebAuthn, ASCredential integration, and the new Digital Credentials / OpenID4VP request parsing — alongside a steady stream of CMake and Cocoa build-system maintenance. The security fixes cluster tightly around that same surface: a missing message check on security origin in WebAuthn IPC, null-deref and crash fixes in PIN callbacks, bounds checks in SPKI/PKCS8 key import, and two safe-browsing races where navigation and downloads proceeded before the lookup returned. Systematic-variant candidate: OpenID4VP request parsing was just moved into the web content process behind an off-by-default flag, so the attacker-controlled parsing path is new, lightly exercised, and sits next to code that has already yielded an origin message-check bug — worth enabling the flag and fuzzing the signed/multisigned request parsers.
Components
Security Fix History
- 2026-09-12 Improve pasteboard type checks on macOS 2026-W37
- 2026-09-10 Popunder bypass via overlappping transient activations · CVE-2026-43804
- 2026-09-09 Cherry-pick 7fdaeaab71b9. rdar://175673904 · CVE-2026-43795
- 2026-08-27 [WebAuthn] Perform validation of related origins 2026-W34
- 2026-06-16 Message check security origin during webauthn calls
- 2026-06-11 Same user gesture can be used for both opening a window and focussing previous one ·
- 2026-06-06 Show safe browsing warning immediately when lookup completes ·
- 2026-06-05 We should wait until we get a safe browsing response before proceeding with downloads · CVE-2026-28971
- 2026-03-06 [Security] Null pointer dereference and wrong-field use in extensions toJSON
Hardening Commits
Recent Commits
- 2026-09-12 Improve pasteboard type checks on macOS 2026-W37
- 2026-09-10 Popunder bypass via overlappping transient activations · CVE-2026-43804
- 2026-09-09 Cherry-pick 7fdaeaab71b9. rdar://175673904 · CVE-2026-43795
- 2026-08-27 [WebAuthn] Perform validation of related origins 2026-W34
- 2026-08-26 [WebAuthn] Smart card is inaccessible to other clients during ceremony
- 2026-08-12 Wire up the virtual wallet mock for OpenID4VP signed and multisigned protocols
- 2026-08-03 REGRESSION(318122@main): http/wpt/identity/digital-credential-openid4vp-request-parsing.https.html is consistently faili
- 2026-07-28 [Digital Credentials] Start to parse OpenID4VP signed and multisigned requests in the web content process
- 2026-07-21 Add OpenID4VP presentation protocols behind an off-by-default flag
- 2026-07-13 Migrate ASCredentialUpdater to ASCredentialDataManager
- 2026-07-10 [WebAuthn] Null check m_pendingRequest before dereferencing it in PIN callbacks
- 2026-07-08 [CMake] WebCore.framework is missing its private module map
- 2026-07-08 [CMake] TestWebKitAPI is missing the mac GamepadMappings sources and the HID framework link
- 2026-07-08 [CMake] Enable AV1 on Cocoa now that dav1d builds with CMake
- 2026-07-08 [CMake] Preprocess the sandbox profiles with the target SDK's -isysroot