Created attachment 73893 [details] Repro Repro: <body><x> <script type="text/javascript"> document.designMode="on"; document.execCommand("selectAll"); document.writeln('<style>* {visibility:collapse}</style>'); document.execCommand("InsertHTML", false, 'x'); </script> id: chrome.dll!WebCore::ReplaceSelectionCommand::doApply ReadAV@NULL (80567d0c1853fec9161cc17f3eeaa01d) description: Attempt to read from unallocated NULL pointer+0x24 in chrome.dll!WebCore::ReplaceSelectionCommand::doApply application: Chromium 9.0.580.0 stack: chrome.dll!WebCore::ReplaceSelectionCommand::doApply chrome.dll!WebCore::EditCommand::apply chrome.dll!WebCore::applyCommand chrome.dll!WebCore::executeInsertFragment chrome.dll!WebCore::executeInsertHTML chrome.dll!WebCore::Editor::Command::execute chrome.dll!WebCore::Document::execCommand chrome.dll!WebCore::DocumentInternal::execCommandCallback chrome.dll!v8::internal::HandleApiCallHelper<...> chrome.dll!v8::internal::Builtin_HandleApiCall chrome.dll!v8::internal::Invoke chrome.dll!v8::internal::Execution::Call chrome.dll!v8::Script::Run
I am unable to reproduce any crash with this reproduction in Safari 15.6 on macOS 12.5 but I see following FIXME in Webkit when I search for "ReplaceSelectionCommand": Link - https://github.com/WebKit/WebKit/blob/8afe31a018b11741abdf9b4d5bb973d7c1d9ff05/Source/WebCore/editing/MoveSelectionCommand.cpp#L72 I am not sure on above one whether it is relevant but in below (which seems more relevant): https://github.com/WebKit/WebKit/blob/b308d25de831f4b7d9c1d643fd166417ef4a5c5e/Source/WebCore/editing/ReplaceSelectionCommand.cpp#L1107 I don't see any null ptr but only RefPtr on Line 1140. rniwa@webkit.org - is it "RESOLVED LATER" or we can close that since this crash is not reproducible or ignore me if I am totally wrong here. Thanks!
No longer reproducing -> Config Changed.