Created attachment 62863 [details] Repro case Found as part of cross_fuzz investigation Repro: <body onload="document.open();window.styleMedia.matchMedium();"> id: WebCore::CSSStyleSelector::styleForElement ReadAV@NULL (dc7b32067c1b2c657a6337dd1beb1998) description: Attempt to read from NULL pointer (+0x24) in WebCore::CSSStyleSelector::styleForElement stack: WebCore::CSSStyleSelector::styleForElement WebCore::StyleMedia::matchMedium WebCore::StyleMediaInternal::matchMediumCallback v8::internal::HandleApiCallHelper<...> v8::internal::Builtin_HandleApiCall v8::internal::Invoke v8::internal::Execution::Call ...
Another similar crash, which does not appear to affect latest Chromium: <body onload="document.write();window.media.matchMedium();">
*** This bug has been marked as a duplicate of bug 43677 ***