Created attachment 77211 [details] Repro http://code.google.com/p/chromium/issues/detail?id=67786 Repro: <script> oContext2d=document.getCSSCanvasContext("2d","",0); oContext2d.font="small-caps 1ex fantasy"; </script> id: chrome.dll!WebCore::Font::xHeight ReadAV@NULL (15af5145b4290aa1c6bccd7c516491f9) description: Attempt to read from unallocated NULL pointer+0x30 in chrome.dll!WebCore::Font::xHeight stack: chrome.dll!WebCore::Font::xHeight chrome.dll!WebCore::CSSPrimitiveValue::computeLengthDouble chrome.dll!WebCore::CSSPrimitiveValue::computeLengthFloat chrome.dll!(unknown) chrome.dll!(unknown) chrome.dll!WebCore::CSSStyleSelector::applyPropertyToStyle chrome.dll!WebCore::CanvasRenderingContext2D::setFont chrome.dll!WebCore::CanvasRenderingContext2DInternal::fontAttrSetter chrome.dll!v8::internal::JSObject::SetPropertyWithCallback chrome.dll!v8::internal::JSObject::SetProperty chrome.dll!v8::internal::JSObject::SetProperty chrome.dll!v8::internal::StoreIC::Store chrome.dll!v8::internal::StoreIC_Miss chrome.dll!v8::internal::Invoke chrome.dll!v8::internal::Execution::Call ...
See also bug 57756
Fixed on bug 66291 yes?