pvollan
WebKit security specialist
Summary
pvollan works primarily on WebKit's process sandboxing and platform integration layer — sandbox profile contents, sandbox extension issuance, and the WebContent/Network process division of trust — with a secondary concentration in Site Isolation, specifically cross-origin iframe rendering and back/forward navigation restore. The security fixes cluster almost entirely on local file load authorization: a tight sequence in early July relocated the sandbox extension check for local file loads from the WebContent process into the Network process, tightened FormDataReference extension validation, and cut off temp-directory loads, a shape that reads as variant analysis over one trust-boundary flaw rather than unrelated reports. Systematic-variant candidate: other paths that mint or consume sandbox extensions outside `NetworkResourceLoader::startNetworkLoad`, and the Site Isolation back-navigation restore code, which has absorbed repeated re-fixes for the same symptom across several months.
Components
Security Fix History
- 2026-08-25 Use-after-free of ScriptExecutionContext in trustedTypeCompliantString ·
- 2026-08-22 [macOS] The Networking process sandbox should inherit network access from the UI process
- 2026-07-02 Restrict ability for Network process to load files from temp directory · CVE-2026-43821
- 2026-07-02 Unable to upload PDF file on iOS ·
- 2026-07-02 [macOS] Enable feature to block local file loads without a sandbox extension ·
- 2026-07-02 FormDataReference validator accepts invalid sandbox extensions ·
- 2026-07-01 Local file loads should always be checked in NetworkResourceLoader::startNetworkLoad ·
- 2026-07-01 The Network process should not create form data sandbox extensions ·
- 2026-06-13 Move sandbox extension check related to local file loads from the WebContent process to the Networking process ·
- 2026-06-05 Embedded content does not load in News App ·
Hardening Commits
- 2026-09-11 There is no need to issue file sandbox extensions from the temp and cache folder
- 2026-08-22 [macOS] The Networking process sandbox should inherit network access from the UI process
- 2026-07-02 Restrict ability for Network process to load files from temp directory · CVE-2026-43821
- 2026-07-02 [macOS] Enable feature to block local file loads without a sandbox extension ·
- 2026-07-01 The Network process should not create form data sandbox extensions ·
- 2026-06-08 [iOS] The UI process should not have access to the temp and cache folder of the Networking process
- 2026-05-20 [iOS] Use temp directories per App for extensions
- 2026-05-18 Move GPU process's temp directory to container
- 2026-05-15 Add launch constraints for XPC services
- 2026-04-27 [macOS] Limit some sandbox read accesses to internal builds
Recent Commits
- 2026-09-18 [iOS] Fix simulated crash in the WebContent process
- 2026-09-18 [Site Isolation] CNN.com ads in separate process don’t open new window
- 2026-09-18 [iOS] Fix simulated WebContent crash
- 2026-09-15 [Site Isolation] Safari crashes after navigating to Instagram through embedded post
- 2026-09-14 Remove CPU core check in defaultUseGPUProcessForDOMRenderingEnabled
- 2026-09-14 Revert 320565@main
- 2026-09-11 There is no need to issue file sandbox extensions from the temp and cache folder
- 2026-09-11 Back navigation fails to restore website after playing an embedded cross-origin YouTube video
- 2026-09-11 [Site Isolation] Video in cross-origin iframe is sometimes not rendering after navigating back
- 2026-09-10 Avoid including util.sb in sandboxes
- 2026-09-09 Dock web apps can get stuck loading
- 2026-09-05 Fix simulated crash in the WebContent process
- 2026-09-05 [Site Isolation] Cross-origin iframe is not always rendering after navigating back
- 2026-08-25 Use-after-free of ScriptExecutionContext in trustedTypeCompliantString ·
- 2026-08-24 [Site Isolation] Cross origin iframe is not rendering after back navigation