Created attachment 593144 [details] gdb output The mCx field of a PreciseGCRunnable can become dangling if the window is closed. With MallocScribble=1, this will usually crash [@ JSRuntime::onOwnerThread]. The testcase from the fuzzer looks something like this, but I had trouble reducing it all the way. fuzzPriv.schedulePreciseGC(); window.open("data:text/html,1"); fuzzPriv.closeTabThenQuit();
Is there any reason we can't just use the safe JS context here?
You need to log in before you can comment on or make changes to this bug.