| Summary: | AXObjectCache::characterOffsetFromVisiblePosition can deref a nullptr when underlying renderer is destroyed | ||||||
|---|---|---|---|---|---|---|---|
| Product: | WebKit | Reporter: | Tyler Wilcock <tyler_w> | ||||
| Component: | Accessibility | Assignee: | Tyler Wilcock <tyler_w> | ||||
| Status: | RESOLVED FIXED | ||||||
| Severity: | Normal | CC: | aboxhall, andresg_22, apinheiro, cfleizach, dmazzoni, ews-watchlist, jcraig, jdiggs, samuel_white, webkit-bug-importer | ||||
| Priority: | P2 | Keywords: | InRadar | ||||
| Version: | Other | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Attachments: |
|
||||||
|
Description
Tyler Wilcock
2023-03-30 23:41:56 PDT
Created attachment 465696 [details]
Patch
Do we still want to check that this is NOT null first? deepPos.deprecatedNode(); (In reply to chris fleizach from comment #4) > Do we still want to check that this is NOT null first? > > deepPos.deprecatedNode(); We should be safe because if `deepPos.deprecatedNode()` were null, this check just above dereferencing it would return: if (visiblePos.isNull()) return CharacterOffset(); Committed 262432@main (7d93b07962d5): <https://commits.webkit.org/262432@main> All reviewed patches have been landed. Closing bug and clearing flags on attachment 465696 [details]. |