The crash occurs in the following lines of removeImplicitlyStyledElement when mapValue is null and extractedStyle is not null: if (extractedStyle) extractedStyle->setProperty(equivalent.propertyID, mapValue->cssText());
Created attachment 71967 [details] demo
http://crbug.com/59992
Created attachment 71969 [details] fixes the crash
Comment on attachment 71969 [details] fixes the crash ok
(In reply to comment #4) > (From update of attachment 71969 [details]) > ok wow, that was really quick! I'll appreciate if you can take a look at https://bugs.webkit.org/show_bug.cgi?id=48349 since it's a security bug. I just cc-ed you on the bug.
Thanks for the review, Kent. Landed as http://trac.webkit.org/changeset/70593.