The functions WebChromeClient::customHighlightRect() and WebChromeClient::paintCustomHighlight() get passed a node. With Changeset 40871 (committed 2009-02-11), the passed node can be 0, which results in a crash. I include a test case which crashes when opening.
Created attachment 30771 [details] Test case - crashes on loading
I forgot to mention that the problem is triggered by having generated content in the document (via h1:empty:before {content:"some text";} in this case). I do not know whether this is the only way to trigger the problem, though.
paintCustomHighlight and the SPI that relied on it have been removed via bug 128456.