← All reports
15 picks from 427 commits
2026-09-05 – 11

This Week in WebKit

427
Total commits
10
Security fixes
6 deep-dive — 4 High, 2 Medium; 4 appendix
108
Contributors
Top components WebCore · WebKit · Other · JSC · Platform

Featured

Security fixes

Notable development

Other security-relevant changes

  • [WebKit UIProcess / clipboard access] (IPC validation bypass) 173261c — clipboard 접근 경로가 강화되었습니다. 기존에는 WebContent process가 전달하는 주장을 신뢰했지만, 이제 UIProcess가 frame의 transient activation을 직접 검증합니다. 그 결과 WebContent process가 장악된 상황에서 activation 상태를 위조해 clipboard 읽기 제한을 우회하는 경로가 차단됩니다.
  • [WebCore SVG animation] (unsigned integer overflow) 28da9c5 — SVGSMILElement의 repeat-count 계산에 clamping이 적용되어 overflow가 방지되었습니다. 또한 seek 중 발생하는 repeat event를 하나로 합쳐, 반복 횟수가 제한 없이 늘어나는 상황도 제거되었습니다. indefinite repeatCount로 seek할 때 발생하던 crash가 함께 수정되었습니다.
  • [WebCore loader] (popunder) a37a650 — popunder 우회가 수정되었습니다. 이미 존재하는 named window에 focus를 주기 전, opener 쪽에 transient activation이 있는지 확인하도록 조건이 추가되었습니다. 이로써 user activation이 겹치는 틈을 이용해 popup이 focus를 다시 가져가는 동작을 막게 됩니다.
  • [WebCore WebAuthn] (OOB read) 79d7541 — CBOR 기반 WebAuthn extension parser에서 서로 다른 container의 iterator를 섞어 쓰는 문제가 수정되었습니다. iterator를 엉뚱한 container의 end()와 비교하고 있었기 때문에, credProps에 'rk' key가 없는 경우 out-of-bounds dereference가 발생했습니다.