shallawa

WebCore security specialist

80 commits (11mo)
16 security fixes
3 hardening
View all commits on GitHub ↗

Summary

shallawa works primarily in WebCore's graphics and imaging stack: ImageBuffer backends, CoreGraphics path and filter rendering, and the decoder work behind the WebCodecs Image API (enabled by default this month) and HTML-in-Canvas. The security fixes sit inside exactly that actively-churning code and fall into recurring shapes — thread-safety failures as decode moved onto worker threads (PathCG scratch context, `PathCG::strokeContains`, `ImageDecoderFactoryAVF`), uninitialized `PixelBuffer` contents escaping filter and readback paths (`FEGaussianBlur` on alpha inputs, `FilterImage`), and GPU-process code allocating or pixel-accessing ImageBuffer backends that don't support it (DisplayList, PDF) — alongside a cross-origin taint miss when a canvas is captured as a VideoFrame. Systematic-variant candidate: shared or static CoreGraphics state newly reachable from the async decode path, and any RemoteRenderingBackend IPC entry point that assumes a concrete backend type rather than validating the RenderingMode it was handed.

Components

WebCore
60%
WebKit
20%
Platform
10%
WTF
6%
WebGPU
1%
GPU Process
1%

Security Fix History

1 / 2

Hardening Commits

Recent Commits

1 / 6

← All Contributors