This Week in WebKit
Featured
Any page can drop the speech object and have a deferred main-thread callback dispatch through freed memory. Something in that callback was protected — just not the object it calls into.
A compromised WebContent process can slip a file:// URL past the one check written to stop it. The gap arrived with the patch that added that check.
A page driving WebGPU can tear down the connection mid-completion and leave two threads decrementing one non-atomic refcount. The outer object was thread-safe.
A content process only has to send an audio-hardware message to make the UI process dispatch into a client that is already gone. No client owns the cache that kept it alive.
Validation covered zero and nothing above it; script-chosen dimensions reached a third-party encoder untouched. The new bound is 32767, which is its own tell.
A guard that is never bypassed can still stop covering the access behind it. The index register the load actually used was defined by nothing at all.
Security fixes
Notable development
-
Local Network Access check lands in NetworkProcess
feature WebKit NetworkProcess / Local Network Access
-
Documents finally get their own IP address space
feature WebCore Loader / Local Network Access
-
Backend handoff reworked for remote ImageBuffers
optimization WebKit GPU Process / Remote Rendering
-
Integer underflow in the OpenType VORG table size computation
hardening WebCore Font Parsing
-
IsoSubspaces share a single default aligned-memory allocator
optimization JavaScriptCore Heap
-
RegExpTestInline extends to quantifiers, alternation, and unicode flags
optimization JavaScriptCore DFG/FTL JIT
-
Swift IPC receivers get a throwing MESSAGE_CHECK
hardening WebKit IPC / UIProcess
-
[GPUProcess] Move the drawing Font functionalities to a new class named FontBase
refactor WebCore Graphics / GPU Process
Other security-relevant changes
- [WebKit UIProcess / clipboard access] (IPC validation bypass)
173261c— clipboard 접근 경로가 강화되었습니다. 기존에는 WebContent process가 전달하는 주장을 신뢰했지만, 이제 UIProcess가 frame의 transient activation을 직접 검증합니다. 그 결과 WebContent process가 장악된 상황에서 activation 상태를 위조해 clipboard 읽기 제한을 우회하는 경로가 차단됩니다. - [WebCore SVG animation] (unsigned integer overflow)
28da9c5—SVGSMILElement의 repeat-count 계산에 clamping이 적용되어 overflow가 방지되었습니다. 또한 seek 중 발생하는 repeat event를 하나로 합쳐, 반복 횟수가 제한 없이 늘어나는 상황도 제거되었습니다. indefinite repeatCount로 seek할 때 발생하던 crash가 함께 수정되었습니다. - [WebCore loader] (popunder)
a37a650— popunder 우회가 수정되었습니다. 이미 존재하는 named window에 focus를 주기 전, opener 쪽에 transient activation이 있는지 확인하도록 조건이 추가되었습니다. 이로써 user activation이 겹치는 틈을 이용해 popup이 focus를 다시 가져가는 동작을 막게 됩니다. - [WebCore WebAuthn] (OOB read)
79d7541— CBOR 기반 WebAuthn extension parser에서 서로 다른 container의 iterator를 섞어 쓰는 문제가 수정되었습니다. iterator를 엉뚱한 container의end()와 비교하고 있었기 때문에, credProps에'rk'key가 없는 경우 out-of-bounds dereference가 발생했습니다.