szewai

WebKit security specialist

148 commits (10mo)
7 security fixes
11 hardening
View all commits on GitHub ↗

Summary

szewai works almost entirely in the WebKit2 process layer on Site Isolation: BrowsingContextGroup registration, frame/process lifetime and teardown ordering, drawing-area swaps across process changes, and the shared process mode with its persistent IsolatedSiteStore. The security-classified work is narrow but uniform in kind — connection-to-identifier authorization checks on storage IPC (DOMCache, FileSystemHandle) — alongside policy fences that keep loopback/local-network and high-value fraud-target domains out of the shared process, and IPC surface gated behind AllowTestOnlyIPC. Where to look next: shared process mode is recent code that carries isolation-relevant invariants, and this contributor's own commit stream already documents those invariants failing — sandbox flags surviving a same-process navigation, a dialog from a document the page has left still reaching the client, frame processes terminated before pageswap and unload handlers run, and find-in-page leaking per-process match counts. Each is a cross-process state-synchronization bug in the same subsystem, which makes the shared-process paths a reasonable place to sweep for variants.

Components

WebKit
52%
Site Isolation
21%
WebCore
20%
Other
4%
Platform
2%
WTF
1%

Security Fix History

Hardening Commits

1 / 2

Recent Commits

1 / 10

← All Contributors