It would be needed to make some extra checks at AccessibilityObject::visiblePositionRangeForRange to make sure toRenderText() function is called with valid parameters, that is, a RenderObject returning 'true when calling to its isText() method. This check is needed because current code doesn't do it and could be executed with RenderObjects other than instances of the RenderText subclass, resulting in failures such as the one in the following stack trace: http://webkit-bots.igalia.com/i386/svn_64534.core-when_1280823420-_-who_testatk-_-why_11.26739.trace.html I'm now building WK with a patch for this. Will attach it as soon as I tested it.
Adding Xan to CC
Created attachment 63331 [details] Patch proposal This patch just adds the needed checks that should have been added before, along with fix for bug 25677 (my fault)
Comment on attachment 63331 [details] Patch proposal OK
Comment on attachment 63331 [details] Patch proposal Clearing flags on attachment: 63331 Committed r64721: <http://trac.webkit.org/changeset/64721>
All reviewed patches have been landed. Closing bug.