Main-process crash (EXC_BAD_ACCESS / heap UAF) when destroying a <webview> with an attached webContents.debugger session · Issue #53819 · electron/electron · GitHub
Skip to content
Navigation Menu
Sign in Appearance settings
* Platform
* AI CODE CREATION
* GitHub Copilot Write better code with AI
* GitHub Copilot app Direct agents from issue to merge
* MCP Registry Integrate external tools
* DEVELOPER WORKFLOWS
* Actions Automate any workflow
* Codespaces Instant dev environments
* Issues Plan and track work
* Code Review Manage code changes
* Code Quality Enforce quality at merge
* APPLICATION SECURITY
* GitHub Advanced Security Find and fix vulnerabilities
* Code security Secure your code as you build
* Secret protection Stop leaks before they start
* EXPLORE
* Why GitHub
* Documentation
* Blog
* Changelog
* Marketplace
View all features
* Solutions
* BY COMPANY SIZE
* Enterprises
* Small and medium teams
* Startups
* Nonprofits
* BY USE CASE
* App Modernization
* DevSecOps
* DevOps
* CI/CD
* View all use cases
* BY INDUSTRY
* Healthcare
* Financial services
* Manufacturing
* Government
* View all industries
View all solutions
* Resources
* EXPLORE BY TOPIC
* AI
* Software Development
* DevOps
* Security
* View all topics
* EXPLORE BY TYPE
* Customer stories
* Events & webinars
* Ebooks & reports
* Business insights
* GitHub Skills
* SUPPORT & SERVICES
* Documentation
* Customer support
* Community forum
* Trust center
* Partners
View all resources
* Open Source
* COMMUNITY
* GitHub Sponsors Fund open source developers
* PROGRAMS
* Security Lab
* Maintainer Community
* GitHub Stars
* Archive Program
* REPOSITORIES
* Topics
* Trending
* Collections
* Enterprise
* ENTERPRISE SOLUTIONS
* Enterprise platform AI-powered developer platform
* AVAILABLE ADD-ONS
* GitHub Advanced Security Enterprise-grade security features
* Copilot for Business Enterprise-grade AI features
* Premium Support Enterprise-grade 24/7 support
* Pricing
Search /
Sign in
Sign up Appearance settings
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert
Uh oh!
There was an error while loading. Please reload this page .
electron
/
electron
Public
*
Notifications
You must be signed in to change notification settings
*
Fork
17.5k
*
Star
123k
*
Code
*
Issues
627
*
Pull requests
125
*
Actions
*
Projects
*
Security and quality
61
*
Insights
Additional navigation options
*
Code
*
Issues
*
Pull requests
*
Actions
*
Projects
*
Security and quality
*
Insights
Main-process crash (EXC_BAD_ACCESS / heap UAF) when destroying a <webview> with an attached webContents.debugger session #53819
New issue
Copy link
New issue
Copy link
Open
Bug
Open
Main-process crash (EXC_BAD_ACCESS / heap UAF) when destroying a <webview> with an attached webContents.debugger session #53819
Bug
Copy link
Labels
43-x-y bug 🪲 platform/macOS
Description
regrlomon
opened on Sep 10, 2026
Issue body actions
Preflight Checklist
* I have read the Contributing Guidelines for this project.
* I agree to follow the Code of Conduct that this project adheres to.
* I have searched the issue tracker for a bug report that matches the one I want to file, without success.
Electron Version
43.1.1
What operating system(s) are you using?
macOS
Operating System Version
macOS arm64 (OS X 26.4.1, 25E253)
What arch are you using?
x64
Last Known Working Electron version
No response
Does the issue also appear in Chromium / Google Chrome?
I don't know how to test
Expected Behavior
Destroying (unmounting from the DOM) a tag whose guest webContents has a webContents.debugger CDP session attached should never crash the main (browser) process. Detaching the debugger before destroying the webview, with arbitrary delay, should make it safe.
Actual Behavior
The main process crashes (whole app dies) when a <webview> is destroyed while/after a CDP session was attached to it. Three distinct crash signatures observed, all on Thread 0 CrBrowserMain :
1) Null-deref in RenderFrameDevToolsAgentHost during navigation notifications (observed both in production and in the minimal repro):
0 Electron Framework!content::RenderFrameDevToolsAgentHost::UpdateFrameHost(content::RenderFrameHostImpl*) [render_frame_devtools_agent_host.cc:1082] (EXC_BAD_ACCESS, addr 0x28)
1 Electron Framework!content::RenderFrameDevToolsAgentHost::ReadyToCommitNavigation(content::NavigationHandle*) [:518]
2 Electron Framework!content::WebContentsImpl::WebContentsObserverList::NotifyObservers<...>
3 Electron Framework!content::WebContentsImpl::ReadyToCommitNavigation(content::NavigationHandle*) [web_contents_impl.cc:7761]
4 Electron Framework!content::NavigationRequest::ReadyToCommitNavigation(bool)
5 Electron Framework!content::NavigationRequest::CommitNavigation() [navigation_request.cc:6915]
Variant: same class, OnNavigationRequestWillBeSent (render_frame_devtools_agent_host.cc:748, addr 0x20).
2) Heap use-after-free in DevToolsSession message dispatch (register x1 = 0xcdcdcdcdcdcdcdcd — destroyed-object fill pattern):
0 Electron Framework!content::DevToolsSession::DispatchProtocolResponseOrNotification(...) [devtools_session.cc:602] (EXC_BAD_ACCESS)
1 Electron Framework!content::DevToolsSession::DispatchProtocolNotification(...)
3) CHECK failure while re-launching the guest renderer process after remount (SIGTRAP / EXC_BREAKPOINT):
0 Electron Framework!electron::ElectronBrowserClient::AppendExtraCommandLineSwitches(...) [immediate_crash.h:180]
1 Electron Framework!content::RenderProcessHostImpl::AppendRendererCommandLine [render_process_host_impl.cc:3714]
2 Electron Framework!content::RenderProcessHostImpl::Init() [render_process_host_impl.cc:2041]
3 Electron Framework!content::RenderFrameHostManager::InitRenderView(...)
4 Electron Framework!content::WebContentsImpl::AttachInnerWebContentsImpl(...) [web_contents_impl.cc:3365]
5 Electron Framework!electron::WebViewGuestDelegate::AttachToIframe(...)
How to reproduce
Two files, no build step, no external dependencies beyond
[email protected] itself.
main.js
const { app , BrowserWindow , crashReporter } = require ( 'electron' ) ;
crashReporter . start ( { submitURL : 'http://127.0.0.1' , uploadToServer : false } ) ;
const HAMMER_MS = 20 ; // CDP command interval, mimics an automation agent
const REMOUNT_MS = 1500 ; // destroy & recreate the <webview>, mimics a React remount
app . whenReady ( ) . then ( ( ) => {
const win = new BrowserWindow ( {
width : 960 , height : 720 ,
webPreferences : { webviewTag : true } ,
} ) ;
win . loadFile ( 'host.html' ) ;
// attach a debugger to every guest webContents and keep a high CDP message rate
app . on ( 'web-contents-created' , ( _e , contents ) => {
if ( contents . getType ( ) !== 'webview' ) return ;
try { contents . debugger . attach ( '1.3' ) ; } catch { }
let n = 0 ;
const timer = setInterval ( ( ) => {
if ( contents . isDestroyed ( ) ) { clearInterval ( timer ) ; return ; }
if ( ! contents . debugger . isAttached ( ) ) { try { contents . debugger . attach ( '1.3' ) ; } catch { return ; } }
const p = ( n % 10 === 0 )
? contents . debugger . sendCommand ( 'Runtime.enable' )
: contents . debugger . sendCommand ( 'Runtime.evaluate' , { expression : '1+1' } ) ;
p . catch ( ( ) => { } ) ;
n ++ ;
} , HAMMER_MS ) ;
contents . on ( 'destroyed' , ( ) => clearInterval ( timer ) ) ;
} ) ;
} ) ;
setTimeout ( ( ) => app . exit ( 0 ) , 90000 ) . unref ( ) ;
app . on ( 'window-all-closed' , ( ) => app . quit ( ) ) ;
host.html
<!doctype html >
< html > < body style =" font:13px/1.5 monospace;margin:8px " >
< div id =" stat " > remount #0 </ div >
< webview id =" wv " src =" https://www.zhipin.com/ " style =" width:900px;height:560px " > </ webview >
< script >
// destroy & recreate the webview every 1.5s (like a React remount)
let n = 0 ;
setInterval ( function ( ) {
const old = document . getElementById ( 'wv' ) ;
const fresh = document . createElement ( 'webview' ) ;
fresh . id = 'wv' ;
fresh . src = 'https://www.zhipin.com/' ;
fresh . style . cssText = 'width:900px;height:560px' ;
old . replaceWith ( fresh ) ;
n ++ ;
document . getElementById ( 'stat' ) . textContent = 'remount #' + n ;
} , 1500 ) ;
</ script >
</ body > </ html >
Run:
npm init -y && npm i
[email protected]
npx electron main.js
Crash usually occurs within 10–20 remount cycles (15–30 s). Reproduces faster with a content-heavy site on a slower network (wide navigation-timing window); a lightweight page (e.g. example.com) may survive many more cycles, but the mechanism is identical.
Control experiments (all on the same page/network)
Setup
Result
BrowserWindow + attached debugger + reload() every 3 s (webContents never destroyed)
No crash (1649 CDP commands, 13 reloads)
<webview> + attached debugger + repeated navigation, webview never destroyed
No crash (22 reloads)
Reproducer as above (webview destroyed & recreated)
Crash (all 3 signatures above)
Reproducer + debugger.detach() on all guests right before destroying
Still crashes
Reproducer + detach() + 500 ms delay before destroying
Still crashes (7 remounts)
This isolates the crash to the combination of "CDP session was attached" + "webview element destroyed" : navigation traffic and CDP load alone are safe; destroying a webview that ever had a session attached is not — and JS-level detach (even with delay) does not make destruction safe, which suggests the internal DevTools session teardown (mojo) is not synchronized with the guest teardown in the browser process.
Testcase Gist URL
No response
Additional Information
No response
Reactions are currently unavailable
Activity
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Metadata
Metadata
Assignees
No one assigned
Labels
43-x-y bug 🪲 platform/macOS
Type
Bug
Projects
No projects
Milestone
No milestone
Relationships
None yet
Development
No branches or pull requests
Issue actions
* Open in GitHub Copilot app
Footer
(c) 2026 GitHub, Inc.
Footer navigation
*
Terms
*
Privacy
*
Security
*
Status
*
Community
*
Docs
*
Contact
*
Manage cookies
*
Do not share my personal information
You can’t perform that action at this time.