This Week in WebKit — April 27 - May 3, 2026
Featured
No memory corruption anywhere — the capability itself is the bug. A compromised renderer writes httpOnly cookies for any origin, including ones the site's own script could never set.
Three UIProcess paths handed a compromised renderer's bytes to whatever parser ImageIO picked. No memory-safety bug here — only the surface where one would be worth the most.
Three families of alternate spelling reached the file-URL slot anyway. A compromised renderer picks the path; a user paste into the wrong app does the rest.
Crafted CSS with a positional :has() argument is the whole prerequisite. Element removal never purged the cache — and something later commits what it kept.
A compromised renderer can trip this one and survive it, but only inside the process-swap window a cross-site navigation opens. The check itself was never wrong.
str.codePointAt(i) === undefined folds to a constant on the strength of an exit the optimiser then deletes. Out-of-range indices stop deoptimising.
Security fixes
- Iterator invalidation in `Page::forEachPage` and its sibling walkers
- Tracker lookup tables raced between the WebPrivacy and resolver threads
- `OpaqueJSClass` stores `parentClass` without retaining it
Notable development
-
Enable `SiteIsolationSharedProcessEnabled` by default
feature WebKit UIProcess Site Isolation
-
Report the restored document's identity on back/forward cache commit
bug WebCore Frame Loading
-
Move memory-footprint sampling to a UIProcess `MemoryFootprintMonitor`
hardening WebKit UIProcess
-
Auto-generate catch-and-default-reply wrappers for Swift IPC receivers
refactor WebKit IPC Infrastructure
-
[JSC] Redesign WeakGCSet to match WeakGCMap
refactor JavaScriptCore Heap
-
[JSC] Unify JS Allocators
optimization JavaScriptCore Heap
-
Add the notification delegate API surface for the browser.notifications web extension API
feature WebKit Web Extensions
Other security-relevant changes
- [JSC Wasm] (race condition, UAF)
b9d4779—finalizeWasmCalleeCleanup에 cross-modifying-code fence가 추가되었습니다. 이를 통해 현재 thread가 패치된 모든 호출 지점을 관찰하도록 보장하며, 이미 해제된 BBQCallee를 stale 상태로 호출하는 상황을 방지합니다. 이론적인 문제이며, 실제 검증은 이루어지지 않았습니다. - [WebKit Mac accessibility] (UAF)
430a7b5— accessibility wrapper가 raw pointer로 반환되는 구조였습니다. 마지막 strong reference인AXIsolatedTree가 scope를 벗어나는 시점에 wrapper가 해제되었고, AppKit이 retain하기 전에 이미 없어진 상태가 되었습니다. 수정에서는RetainPtr::autorelease()로 감싸 lifetime을 연장했습니다. - [WebKit UIProcess speech recognition] (hardening)
49e046b— speech recognition IPC handler에서numberOfFrames에 대한 bounds 검증이 추가되었습니다. 신뢰할 수 없는 WebContent가 특권을 가진 UI process 쪽에서 크기 제한 없는 audio buffer 할당을 유발하는 경로를 차단합니다. - [WebCore WebGL] (incorrect state)
b871911— WebGL texture upload 과정의 premultiplication 상태 처리 regression이 수정되었습니다. 기존에는 framework 초기화 시점에 상태를 결정했지만, 이제 호출 지점에서 결정하도록 변경되었습니다. - [WebKit NetworkProcess / WebSocket] (same-site bypass)
c876f70— WebSocket task는_siteForCookies를 전혀 설정하지 않았습니다. 그 결과 CFNetwork가 SameSite 속성과 무관하게 일치하는 cookie를 모두 붙여 보냈습니다. 수정에서는 task 생성 시점에updateTaskWithFirstPartyForSameSiteCookies()를 호출하여, same-site cookie 필터링과 CSRF 방어를 복원했습니다. - [WebCore ControlFactory] (hardening)
9289509—RemoteGraphicsContext가 work queue에서 파괴될 때ControlFactoryMac이 캐싱해 둔 AppKitNSCell인스턴스도 main thread가 아닌 곳에서 파괴되면서 GPU process crash가 발생했습니다.ControlFactory의 파괴가 main run loop에서 수행되도록 보장하여, thread-safe하지 않은 해제를 막았습니다. - [WebCore FloatingObjects] (stale state)
5de3fda— line content를 버리는 시점에 suspended list에 남아 있던 stale float을 제거하도록 변경되어, 동일한 float이 두 번 배치되는 문제를 방지합니다. 또한 float의 위치를 갱신할 때 spatial tree의 key를 다시 잡아주는placeFloatingBox()가 추가되었습니다. - [WebKit NetworkProcess WebTransport] (proxy bypass)
d7912bc— WebTransport connection에는 application identifier나 tracker 상태가 표시되지 않았습니다. 그래서 routing이 정확하게 이루어지지 않았고, proxy를 거쳐야 할 connection이 직접 연결되는 경우가 있었습니다. 패치에서는 기존 WebRTC helper를 재사용하되, 새로운IsRTC파라미터로 RTC 전용 동작을 구분하도록 했습니다.