Created attachment 44039 [details]
Looks like there's a double-delete of the BSTRs here. updateGlobalHistory creates WebCore::BStrings and passes them to WebNavigationData::createInstance, which tries to adopt the BSTRs that the BStrings wrap. But the BStrings haven't given up ownership!
style-queue ran check-webkit-style on attachment 44039 [details] without any errors.
Committed r51510: <http://trac.webkit.org/changeset/51510>
Comment on attachment 44039 [details]
Clearing r? on a committed patch.