Created attachment 33701 [details] Example On the attached file, see the line 228 to 236 : .content{ -webkit-transition-property: -webkit-transform; -webkit-transition-duration: 5s; -webkit-transition-timing-function: cubic-bezier(0.2, 0.6, 0.6, 0.9); -webkit-transform: translate3d(0, 0, 0); -webkit-column-count:0; overflow:hidden;/* only this line can generate a bug too */ display:table-row;/*only this line can generate a bug too */ } This CSS class crash the browser (I think it's a buffer overflow error... If anyone can confirm :).
I only see a crash with display: table-row present. The overflow: hidden does not appear to be relevant at all. It's a simple null-dereference.
<rdar://problem/7101325>
Created attachment 33727 [details] Patch, testcase, changelog
http://trac.webkit.org/changeset/46549