For greater than 2 character push back, unconsumeCharacters() in WebCore/xml/parser/CharacterReferenceParserInlines.h extracts text from the StringBuilder argument as a 16 bit string even if the StringBuilder contains 8 bit text. Instead, the StringBuilder should be stringified and used directly.
Created attachment 176108 [details]
Comment on attachment 176108 [details]
Clearing flags on attachment: 176108
Committed r135802: <http://trac.webkit.org/changeset/135802>
All reviewed patches have been landed. Closing bug.