squelart

WebCore security specialist

36 commits (10mo)
3 security fixes
5 hardening
View all commits on GitHub ↗

Summary

squelart works almost entirely in WebCore's canvas and pixel-buffer layer — HDR and float16 canvas support, the ArrayPixelBuffer/TypedArrayPixelBuffer refactor, color-space plumbing through ImageData and ShareableBitmapConfiguration, and the convertImagePixels conversion paths. The security and hardening work lands on exactly the surface being extended: buffer-size checks before Float16 conversion, a multiplication overflow in the bytesPerRow() validator, and IOSurface validation on a MachSendRight arriving at WebPageProxy::takeSnapshot(). Systematic-variant candidate: size and stride arithmetic around the newly introduced pixel formats (RGBA16F, BGRX8) and the ImageData constructor paths that only recently became PixelFormat-aware — mismatch handling there is new code guarding old assumptions.

Components

WebCore
74%
WebKit
12%
WTF
6%
Platform
6%
WebGPU
3%

Security Fix History

Hardening Commits

Recent Commits

1 / 3

← All Contributors