Closed Bug 1509050 Opened 6 years ago Closed 4 years ago

Crash in objc_release | CGSWindowInvalidateSize

Categories

(Core :: Widget: Cocoa, defect, P3)

Unspecified
macOS
defect

Tracking

()

RESOLVED WORKSFORME
Tracking Status
firefox-esr60 --- unaffected
firefox63 --- wontfix
firefox64 --- wontfix
firefox65 --- wontfix
firefox66 --- fix-optional
firefox67 --- fix-optional
firefox68 --- fix-optional

People

(Reporter: marcia, Unassigned)

References

Details

(4 keywords)

Crash Data

This bug was filed from the Socorro interface and is
report bp-6050c517-28ac-4467-8f10-aadd90181121.
=============================================================

Seen while looking at crash stats: https://bit.ly/2qVwf7q. Marking as security sensitive since there are potential UAFs in the signature. All crashes are using 10.13. A total of 8 crashes in the last week.

Top 10 frames of crashing thread:

0 libobjc.A.dylib objc_release 
1 SkyLight CGSWindowInvalidateSize 
2 SkyLight shape_window_internal 
3 SkyLight SLSShapeWindowInWindowCoordinates 
4 AppKit __NSCGSWindowMark__block_invoke_2 
5 AppKit _NSCGSWindowEnumerateForCommit 
6 AppKit __NSCGSWindowMark__block_invoke 
7 AppKit NSCGSTransactionRunPreCommitActionsForOrder_ 
8 AppKit NSCGSTransactionRunPreCommitActions_ 
9 AppKit -[_NSCGSTransaction synchronize] 

=============================================================
It looks as if all the URLs are either youtube.com or video sites.
Adding the usual MacOS suspects.
Group: core-security → layout-core-security
This is a very similar (although not identical) stack as in bug 1452763.
See Also: → 1452763
Priority: -- → P2
Priority: P2 → P3

I found some additional crashes when looking at nightly crash data with a similar signature, they are all 10.14: https://bit.ly/2MVA2Mf. From what I can see from the URLs, a few people are using password managers - https://bitwarden.com/#download is one example. Some of the other URLs are behind logins.

One comment "Attempt to open the Grammarly extension on a Desire2Learn myCourses page. That is all I can think of."

Crash Signature: [@ objc_release | CGSWindowInvalidateSize] → [@ objc_release | CGSWindowInvalidateSize] [@ CGSWindowInvalidateCache]
Group: layout-core-security → core-security-release
Status: NEW → RESOLVED
Closed: 4 years ago
Flags: needinfo?(spohl.mozilla.bugs)
Resolution: --- → WORKSFORME
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.