There's no check on parentNode->renderer() before its used within canBeScrolledIntoView. Associated Chromium fix with layout test https://chromium-review.googlesource.com/c/chromium/src/+/550255
Adding the following in the for loop fixes the problem. + if (UNLIKELY(!parentNode->renderer())) + continue; Its EOD here so if nobody gets to this by Monday I'll just throw together a patch with the layout test in it.
Created attachment 348361 [details] Patch Port of the chromium fix
Comment on attachment 348361 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=348361&action=review > Source/WebCore/page/SpatialNavigation.cpp:708 > + if (UNLIKELY(!parentNode->renderer())) The UNLIKELY() seems unnecessary.
Created attachment 348371 [details] Patch Address review comments
Comment on attachment 348371 [details] Patch Clearing flags on attachment: 348371 Committed r235457: <https://trac.webkit.org/changeset/235457>
All reviewed patches have been landed. Closing bug.
<rdar://problem/43829010>