Closed Bug 1338738 Opened 7 years ago Closed 7 years ago

AV crash in mozilla::a11y::ProxyAccessibleBase<T>::ClearChildDoc

Categories

(Core :: Disability Access APIs, defect)

54 Branch
x86_64
Windows 8
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 1336770

People

(Reporter: qab, Unassigned)

Details

Crash Data

This bug was filed from the Socorro interface and is 
report bp-f194bdce-3a3b-4ed0-af31-7fbef2170211.
=============================================================

Repro steps:

1. Visit http://hello.com
2. Refresh and or repeat step 1

crash occurs

https://crash-stats.mozilla.com/report/index/8a2f135c-662c-40e7-9b6e-5a0de2170211

Looks like an access violation with different addresses
Dupe of bug 1336770? Though the stack here is different and seems to involve JS.

(Updating version field as the crash report is from 54, yesterday's nightly)
Group: firefox-core-security → core-security
Component: Untriaged → Disability Access APIs
Product: Firefox → Core
Version: 52 Branch → 54 Branch
Is this fixed by bug 1339128 (in today's nightly)?

Sure looks like a dupe of bug 1336770 to me, both filed from a huge uptick in crashes on this signature. (see https://ashughes1.github.io/bugzilla-socorro-lens/chart.htm?s=mozilla::a11y::ProxyAccessibleBase%3CT%3E::ClearChildDoc)
Group: core-security
Status: UNCONFIRMED → RESOLVED
Closed: 7 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.