ScriptController.cpp:174 doesn't handle the possibility that the event field on the global object is set to a v8::Object that isn't a DOM wrapper. This can only happen if a script has directly set window.event.
Created attachment 48651 [details] patch
Comment on attachment 48651 [details] patch Ideally fast/dom/Window/window-event-override-no-crash.html should have a newline at the end, but this looks great!
http://trac.webkit.org/changeset/54964 ....and, um, http://trac.webkit.org/changeset/54965