| Summary: | nullptr crash in EventPath::buildPath via FullscreenManager::dispatchFullscreenChangeOrErrorEvent | ||||||
|---|---|---|---|---|---|---|---|
| Product: | WebKit | Reporter: | Michael Saboff <msaboff> | ||||
| Component: | DOM | Assignee: | Ryosuke Niwa <rniwa> | ||||
| Status: | RESOLVED FIXED | ||||||
| Severity: | Normal | CC: | beidson, bfulgham, brandonstewart, cgarcia, csaavedra, fred.wang, gpoo, mmaxfield, msaboff, rbuis, rniwa, webkit-bug-importer, wenson_hsieh | ||||
| Priority: | P2 | Keywords: | InRadar | ||||
| Version: | WebKit Nightly Build | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Attachments: |
|
||||||
|
Description
Michael Saboff
2022-07-05 10:03:57 PDT
The issue is that FullscreenManager doesn't keep JS wrapper of change/error event nodes alive. As a result, GC will happily collect shadow root as well as its host and ancestors. Not a security issue. Pull request: https://github.com/WebKit/WebKit/pull/3074 Committed 253227@main (29c4919ba55f): <https://commits.webkit.org/253227@main> Reviewed commits have been landed. Closing PR #3074 and removing active labels. |