Bug 236622 - Safari 15.2 crashes when degenerate webp images are decoded with createImageBitmap
Summary: Safari 15.2 crashes when degenerate webp images are decoded with createImageB...
Status: RESOLVED DUPLICATE of bug 231794
Alias: None
Product: WebKit
Classification: Unclassified
Component: Images (show other bugs)
Version: Safari 15
Hardware: Mac (Intel) macOS 12
: P2 Normal
Assignee: Nobody
Keywords: InRadar
Depends on:
Reported: 2022-02-14 17:07 PST by ryan.hamley
Modified: 2022-02-18 14:51 PST (History)
3 users (show)

See Also:

Solid black WebP image (54 bytes, image/webp)
2022-02-14 17:07 PST, ryan.hamley
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description ryan.hamley 2022-02-14 17:07:37 PST
Created attachment 451964 [details]
Solid black WebP image

Safari 15.2 and 15.3 crash when decoding certain WebP images with `window.createImageBitmap`. This happens with images that have a channel depth of 1-bit in a channel (e.g. solid color images such as https://bug-219977-attachments.webkit.org/attachment.cgi?id=421723). The underlying WebP issue was logged in https://bugs.webkit.org/show_bug.cgi?id=219977 but previous versions of Safari handled the error gracefully (logging "Cannot decode the data in the argument to createImageBitmap") and error handling in sites/apps could handle the error successfully. Since Safari 15.2, the error isn't handled and causes the tab to crash.

https://jsbin.com/cetawaqudo/edit?js,output is a basic reproduction using the black square image from above.
Comment 1 Radar WebKit Bug Importer 2022-02-14 19:58:42 PST
Comment 2 Alexey Proskuryakov 2022-02-15 16:59:29 PST
This looks like a duplicate of bug 231794. Can you reproduce this with Safari technology Preview?
Comment 3 ryan.hamley 2022-02-16 13:26:34 PST
I couldn't replicate this in Tech Preview 140 so I think this is likely a duplicate and has been fixed. Thanks!
Comment 4 Alexey Proskuryakov 2022-02-18 14:51:38 PST
Thank you for confirming this!

*** This bug has been marked as a duplicate of bug 231794 ***