Crashing in code generated by generateCharacterClassGreedy() with something like "a\u{10410}\u{10410}b".match(/a(\u{10410}*)bc|a(\u{10410}*)b/ui). Looks like we increment "count" before checking is we are at the end of the string.
<rdar://problem/34035972>
Created attachment 318914 [details] Patch
Comment on attachment 318914 [details] Patch r=me
Comment on attachment 318914 [details] Patch Clearing flags on attachment: 318914 Committed r221111: <http://trac.webkit.org/changeset/221111>
All reviewed patches have been landed. Closing bug.