Bug 273187

Summary: Block Function constructor string arguments when trusted types enforced
Product: WebKit Reporter: Luke Warlow <lwarlow>
Component: JavaScriptCoreAssignee: Luke Warlow <lwarlow>
Status: NEW    
Severity: Normal CC: webkit-bug-importer
Priority: P2 Keywords: InRadar
Version: Safari 17   
Hardware: Unspecified   
OS: Unspecified   
See Also: https://github.com/web-platform-tests/wpt/pull/46546
Bug Depends on:    
Bug Blocks: 267694    

Luke Warlow
Reported 2024-04-24 07:51:14 PDT
When trusted types are enforced string arguments to new Function() should be blocked unless the default policy exists and allows them.
Attachments
Luke Warlow
Comment 1 2024-04-29 09:50:07 PDT
Radar WebKit Bug Importer
Comment 2 2024-05-01 07:52:15 PDT
Note You need to log in before you can comment on or make changes to this bug.