WebKit memory disclosure, Splunk, and LiteLLM
Original WebKit research, two lab-rebuilt control-plane flaws, June's wider signal, and six actions for Australian security leaders.
How code-signing, entitlements, and policy daemons combine to enforce trust on modern macOS. Australian Cyber Conference 2026, Melbourne.
↗How a client engagement led to GHSA-q7pc-356p-hggc, affecting SFTPGo through 2.7.4 and fixed in 2.7.5.
→Out-of-bounds read in WebKit's YARR JIT regex engine. Case-insensitive backreferences could disclose process memory through crafted web content; the fix adds the missing bounds check.
↗GlobalProtect authentication override, Exchange OWA mitigation limits, and a measured Australian exposure snapshot.
→The bug class behind a chunk of recent zero-clicks. Integer overflows, missing bounds checks, and why hardened codebases still fall over the same edge.
→An Apple CoreMedia privacy issue that could allow an app to access private information.
↗An Apple ImageIO memory-corruption issue triggered by a maliciously crafted image.
↗An Apple WebKit issue that could let malicious websites process restricted web content outside the sandbox.
↗Managing edge device vulnerabilities in 2025. Melbourne Cyber Conference, invited speaker.
↗Link the article or issue you are referring to and tell us what you need. We reply within one Australian business day.