Created attachment 142031 [details] Repro case See https://code.google.com/p/chromium/issues/detail?id=128222 for more info, but I'll attach the test file here too just in case. I looks to me like when we call BlobBuilder's append(blob), we don't store a reference to the blob anywhere, so it can get garbage-collected before we try to access its data. So far as I know this only affects chromium currently, but the bug's probably all in webcore.