When JavaScriptVariant contains a string and operator= is called with itself the memory will be free'd in 'this' and then a copy will be attempted from 'that' resulting in a crash.
Created attachment 162261 [details] patch
Comment on attachment 162261 [details] patch Clearing flags on attachment: 162261 Committed r127644: <http://trac.webkit.org/changeset/127644>
All reviewed patches have been landed. Closing bug.