There is a difficult-to-reproduce null dereference crash that can occur when WebPage::selectWithGesture() receives a “TapAndAHalf” gesture with state “Changed” when having never received a “TapAndAHalf” gesture with state “Began”.
1. Go to data:text/html,<input>
2. Continuously tap, and tap-press into the text field while simultaneously typing
Created attachment 240995 [details]
Committed r175636: <http://trac.webkit.org/changeset/175636>