http://trac.webkit.org/changeset/58040 modified TextIterator::emitText and it uses RenderText::textWithoutTranscoding which may return String with refcnt==1 . TextIterator::emitText doesn't increment the refcnt of the returned String so the String created by textWithoutTranscoding() will be freed when emitString() finishes. This means we will touch the freed buffer. The test I added in r58040 happened to work for most platforms except chromium-win-debug (maybe because the iterator uses the freed buffer soon after the buffer is freed).
My apologies for this bug.
Created attachment 54028 [details]
*** Bug 37907 has been marked as a duplicate of this bug. ***
Comment on attachment 54028 [details]
+ // Prevent m_textCharacters from being freed.
+ String m_text;
I think this comment is not as clear as it could be, but I don't have any specific suggestions for improving it.
Committed r58149: <http://trac.webkit.org/changeset/58149>