PatchGap · Hunt
Silent-Fix Reports
Most trackers start from a CVE and work back to the commit. These reports go the other way: each week the commit hunter scores every WebKit source commit for security-fix signals, an LLM triages the candidates, and the exploitable-grade ones get a full root-cause analysis, PoC and detection writeup — before any advisory names them.
Weekly reports
5
Vendor
WebKit
Direction
commit → pre-CVE
WebKit
2026-W34
267 commits triaged in the 2026-08-17 - 2026-08-23 window; 47 security, 20 exploitable-grade with full root-cause + detection writeups.
WebKit
2026-W25
264 commits triaged in the 2026-06-15 - 2026-06-21 window; 60 security, 40 exploitable-grade with full root-cause + detection writeups.
WebKit
2026-W23
280 commits triaged in the 2026-06-01 - 2026-06-07 window; 55 security, 21 exploitable-grade with full root-cause + detection writeups.
WebKit
2026-W22
255 commits triaged in the 2026-05-25 - 2026-05-31 window; 71 security, 52 exploitable-grade with full root-cause + detection writeups.
WebKit
2026-W21
228 commits triaged in the 2026-05-18 - 2026-05-24 window; 64 security, 28 exploitable-grade with full root-cause + detection writeups.