From 832f66d34afbe74faf518dc6d47a8ed6496e23e8 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Thu, 16 Jul 2026 14:44:38 +0000 Subject: [PATCH] fix(security): Remove forced downcast when dequeueing annotation views Changed forced downcast (`as!`) to conditional downcast (`as?`) with fallback instantiation for `MKMarkerAnnotationView`. This prevents a potential Denial of Service (DoS) vulnerability via application crash. --- .../mapkit_flutter/Annotations/AnnotationController.swift | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/darwin/mapkit_flutter/Sources/mapkit_flutter/Annotations/AnnotationController.swift b/darwin/mapkit_flutter/Sources/mapkit_flutter/Annotations/AnnotationController.swift index dabe0d0..eb8a3be 100644 --- a/darwin/mapkit_flutter/Sources/mapkit_flutter/Annotations/AnnotationController.swift +++ b/darwin/mapkit_flutter/Sources/mapkit_flutter/Annotations/AnnotationController.swift @@ -69,7 +69,8 @@ extension MapKitViewHost { #endif view = customView } else { - let markerView = self.mapView.dequeueReusableAnnotationView(withIdentifier: "FlutterMarkerAnnotationView", for: annotation) as! MKMarkerAnnotationView + let markerView = self.mapView.dequeueReusableAnnotationView(withIdentifier: "FlutterMarkerAnnotationView", for: annotation) as? MKMarkerAnnotationView + ?? MKMarkerAnnotationView(annotation: annotation, reuseIdentifier: "FlutterMarkerAnnotationView") self.applyMarkerStyle(markerView, annotation.icon) view = markerView }