SOLFIND
Web Lens
Portal home

Main-process crash (EXC_BAD_ACCESS / heap UAF) when destroying a <webview> with an attached webContents.debugger session · Issue #53819 · electron/electron · GitHub

https://github.com/electron/electron/issues/53819 • 315 KB fetched
Open original page


Main-process crash (EXC_BAD_ACCESS / heap UAF) when destroying a <webview> with an attached webContents.debugger session · Issue #53819 · electron/electron · GitHub Skip to content Navigation Menu Sign in Appearance settings * Platform * AI CODE CREATION * GitHub Copilot Write better code with AI * GitHub Copilot app Direct agents from issue to merge * MCP Registry Integrate external tools * DEVELOPER WORKFLOWS * Actions Automate any workflow * Codespaces Instant dev environments * Issues Plan and track work * Code Review Manage code changes * Code Quality Enforce quality at merge * APPLICATION SECURITY * GitHub Advanced Security Find and fix vulnerabilities * Code security Secure your code as you build * Secret protection Stop leaks before they start * EXPLORE * Why GitHub * Documentation * Blog * Changelog * Marketplace View all features * Solutions * BY COMPANY SIZE * Enterprises * Small and medium teams * Startups * Nonprofits * BY USE CASE * App Modernization * DevSecOps * DevOps * CI/CD * View all use cases * BY INDUSTRY * Healthcare * Financial services * Manufacturing * Government * View all industries View all solutions * Resources * EXPLORE BY TOPIC * AI * Software Development * DevOps * Security * View all topics * EXPLORE BY TYPE * Customer stories * Events & webinars * Ebooks & reports * Business insights * GitHub Skills * SUPPORT & SERVICES * Documentation * Customer support * Community forum * Trust center * Partners View all resources * Open Source * COMMUNITY * GitHub Sponsors Fund open source developers * PROGRAMS * Security Lab * Maintainer Community * GitHub Stars * Archive Program * REPOSITORIES * Topics * Trending * Collections * Enterprise * ENTERPRISE SOLUTIONS * Enterprise platform AI-powered developer platform * AVAILABLE ADD-ONS * GitHub Advanced Security Enterprise-grade security features * Copilot for Business Enterprise-grade AI features * Premium Support Enterprise-grade 24/7 support * Pricing Search / Sign in Sign up Appearance settings You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert Uh oh! There was an error while loading. Please reload this page . electron / electron Public * Notifications You must be signed in to change notification settings * Fork 17.5k * Star 123k * Code * Issues 627 * Pull requests 125 * Actions * Projects * Security and quality 61 * Insights Additional navigation options * Code * Issues * Pull requests * Actions * Projects * Security and quality * Insights Main-process crash (EXC_BAD_ACCESS / heap UAF) when destroying a <webview> with an attached webContents.debugger session   #53819 New issue Copy link New issue Copy link Open Bug Open Main-process crash (EXC_BAD_ACCESS / heap UAF) when destroying a <webview> with an attached webContents.debugger session #53819 Bug Copy link Labels 43-x-y bug 🪲 platform/macOS Description regrlomon opened on Sep 10, 2026 Issue body actions Preflight Checklist * I have read the Contributing Guidelines for this project. * I agree to follow the Code of Conduct that this project adheres to. * I have searched the issue tracker for a bug report that matches the one I want to file, without success. Electron Version 43.1.1 What operating system(s) are you using? macOS Operating System Version macOS arm64 (OS X 26.4.1, 25E253) What arch are you using? x64 Last Known Working Electron version No response Does the issue also appear in Chromium / Google Chrome? I don't know how to test Expected Behavior Destroying (unmounting from the DOM) a tag whose guest webContents has a webContents.debugger CDP session attached should never crash the main (browser) process. Detaching the debugger before destroying the webview, with arbitrary delay, should make it safe. Actual Behavior The main process crashes (whole app dies) when a <webview> is destroyed while/after a CDP session was attached to it. Three distinct crash signatures observed, all on Thread 0 CrBrowserMain : 1) Null-deref in RenderFrameDevToolsAgentHost during navigation notifications (observed both in production and in the minimal repro): 0 Electron Framework!content::RenderFrameDevToolsAgentHost::UpdateFrameHost(content::RenderFrameHostImpl*) [render_frame_devtools_agent_host.cc:1082] (EXC_BAD_ACCESS, addr 0x28) 1 Electron Framework!content::RenderFrameDevToolsAgentHost::ReadyToCommitNavigation(content::NavigationHandle*) [:518] 2 Electron Framework!content::WebContentsImpl::WebContentsObserverList::NotifyObservers<...> 3 Electron Framework!content::WebContentsImpl::ReadyToCommitNavigation(content::NavigationHandle*) [web_contents_impl.cc:7761] 4 Electron Framework!content::NavigationRequest::ReadyToCommitNavigation(bool) 5 Electron Framework!content::NavigationRequest::CommitNavigation() [navigation_request.cc:6915] Variant: same class, OnNavigationRequestWillBeSent (render_frame_devtools_agent_host.cc:748, addr 0x20). 2) Heap use-after-free in DevToolsSession message dispatch (register x1 = 0xcdcdcdcdcdcdcdcd — destroyed-object fill pattern): 0 Electron Framework!content::DevToolsSession::DispatchProtocolResponseOrNotification(...) [devtools_session.cc:602] (EXC_BAD_ACCESS) 1 Electron Framework!content::DevToolsSession::DispatchProtocolNotification(...) 3) CHECK failure while re-launching the guest renderer process after remount (SIGTRAP / EXC_BREAKPOINT): 0 Electron Framework!electron::ElectronBrowserClient::AppendExtraCommandLineSwitches(...) [immediate_crash.h:180] 1 Electron Framework!content::RenderProcessHostImpl::AppendRendererCommandLine [render_process_host_impl.cc:3714] 2 Electron Framework!content::RenderProcessHostImpl::Init() [render_process_host_impl.cc:2041] 3 Electron Framework!content::RenderFrameHostManager::InitRenderView(...) 4 Electron Framework!content::WebContentsImpl::AttachInnerWebContentsImpl(...) [web_contents_impl.cc:3365] 5 Electron Framework!electron::WebViewGuestDelegate::AttachToIframe(...) How to reproduce Two files, no build step, no external dependencies beyond [email protected] itself. main.js const { app , BrowserWindow , crashReporter } = require ( 'electron' ) ; crashReporter . start ( { submitURL : 'http://127.0.0.1' , uploadToServer : false } ) ; const HAMMER_MS = 20 ; // CDP command interval, mimics an automation agent const REMOUNT_MS = 1500 ; // destroy & recreate the <webview>, mimics a React remount app . whenReady ( ) . then ( ( ) => { const win = new BrowserWindow ( { width : 960 , height : 720 , webPreferences : { webviewTag : true } , } ) ; win . loadFile ( 'host.html' ) ; // attach a debugger to every guest webContents and keep a high CDP message rate app . on ( 'web-contents-created' , ( _e , contents ) => { if ( contents . getType ( ) !== 'webview' ) return ; try { contents . debugger . attach ( '1.3' ) ; } catch { } let n = 0 ; const timer = setInterval ( ( ) => { if ( contents . isDestroyed ( ) ) { clearInterval ( timer ) ; return ; } if ( ! contents . debugger . isAttached ( ) ) { try { contents . debugger . attach ( '1.3' ) ; } catch { return ; } } const p = ( n % 10 === 0 ) ? contents . debugger . sendCommand ( 'Runtime.enable' ) : contents . debugger . sendCommand ( 'Runtime.evaluate' , { expression : '1+1' } ) ; p . catch ( ( ) => { } ) ; n ++ ; } , HAMMER_MS ) ; contents . on ( 'destroyed' , ( ) => clearInterval ( timer ) ) ; } ) ; } ) ; setTimeout ( ( ) => app . exit ( 0 ) , 90000 ) . unref ( ) ; app . on ( 'window-all-closed' , ( ) => app . quit ( ) ) ; host.html <!doctype html > < html > < body style =" font:13px/1.5 monospace;margin:8px " > < div id =" stat " > remount #0 </ div > < webview id =" wv " src =" https://www.zhipin.com/ " style =" width:900px;height:560px " > </ webview > < script > // destroy & recreate the webview every 1.5s (like a React remount) let n = 0 ; setInterval ( function ( ) { const old = document . getElementById ( 'wv' ) ; const fresh = document . createElement ( 'webview' ) ; fresh . id = 'wv' ; fresh . src = 'https://www.zhipin.com/' ; fresh . style . cssText = 'width:900px;height:560px' ; old . replaceWith ( fresh ) ; n ++ ; document . getElementById ( 'stat' ) . textContent = 'remount #' + n ; } , 1500 ) ; </ script > </ body > </ html > Run: npm init -y && npm i [email protected] npx electron main.js Crash usually occurs within 10–20 remount cycles (15–30 s). Reproduces faster with a content-heavy site on a slower network (wide navigation-timing window); a lightweight page (e.g. example.com) may survive many more cycles, but the mechanism is identical. Control experiments (all on the same page/network) Setup Result BrowserWindow + attached debugger + reload() every 3 s (webContents never destroyed) No crash (1649 CDP commands, 13 reloads) <webview> + attached debugger + repeated navigation, webview never destroyed No crash (22 reloads) Reproducer as above (webview destroyed & recreated) Crash (all 3 signatures above) Reproducer + debugger.detach() on all guests right before destroying Still crashes Reproducer + detach() + 500 ms delay before destroying Still crashes (7 remounts) This isolates the crash to the combination of "CDP session was attached" + "webview element destroyed" : navigation traffic and CDP load alone are safe; destroying a webview that ever had a session attached is not — and JS-level detach (even with delay) does not make destruction safe, which suggests the internal DevTools session teardown (mojo) is not synchronized with the guest teardown in the browser process. Testcase Gist URL No response Additional Information No response Reactions are currently unavailable Activity Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment Metadata Metadata Assignees No one assigned Labels 43-x-y bug 🪲 platform/macOS Type Bug Projects No projects Milestone No milestone Relationships None yet Development No branches or pull requests Issue actions * Open in GitHub Copilot app Footer (c) 2026 GitHub, Inc. Footer navigation * Terms * Privacy * Security * Status * Community * Docs * Contact * Manage cookies * Do not share my personal information You can’t perform that action at this time.

Links found on this page

  1. Skip to content [direct]
  2. Sign in [direct]
  3. GitHub Copilot Write better code with AI [direct]
  4. GitHub Copilot app Direct agents from issue to merge [direct]
  5. MCP Registry Integrate external tools [direct]
  6. Actions Automate any workflow [direct]
  7. Codespaces Instant dev environments [direct]
  8. Issues Plan and track work [direct]
  9. Code Review Manage code changes [direct]
  10. Code Quality Enforce quality at merge [direct]
  11. GitHub Advanced Security Find and fix vulnerabilities [direct]
  12. Code security Secure your code as you build [direct]
  13. Secret protection Stop leaks before they start [direct]
  14. Why GitHub [direct]
  15. Documentation [direct]
  16. Blog [direct]
  17. Changelog [direct]
  18. Marketplace [direct]
  19. View all features [direct]
  20. Enterprises [direct]
  21. Small and medium teams [direct]
  22. Startups [direct]
  23. Nonprofits [direct]
  24. App Modernization [direct]
  25. DevSecOps [direct]
  26. DevOps [direct]
  27. CI/CD [direct]
  28. View all use cases [direct]
  29. Healthcare [direct]
  30. Financial services [direct]
  31. Manufacturing [direct]
  32. Government [direct]
  33. View all industries [direct]
  34. View all solutions [direct]
  35. AI [direct]
  36. Software Development [direct]
  37. DevOps [direct]
  38. Security [direct]
  39. View all topics [direct]
  40. Customer stories [direct]
  41. Events & webinars [direct]
  42. Ebooks & reports [direct]
  43. Business insights [direct]
  44. GitHub Skills [direct]
  45. Customer support [direct]
  46. Community forum [direct]
  47. Trust center [direct]
  48. Partners [direct]
  49. View all resources [direct]
  50. GitHub Sponsors Fund open source developers [direct]
  51. Security Lab [direct]
  52. Maintainer Community [direct]
  53. GitHub Stars [direct]
  54. Archive Program [direct]
  55. Topics [direct]
  56. Trending [direct]
  57. Collections [direct]
  58. Copilot for Business Enterprise-grade AI features [direct]
  59. Premium Support Enterprise-grade 24/7 support [direct]
  60. Pricing [direct]
  61. Sign up [direct]
  62. electron [direct]
  63. electron [direct]
  64. Notifications [direct]
  65. Issues 627 [direct]
  66. Pull requests 125 [direct]
  67. Actions [direct]
  68. Projects [direct]
  69. Security and quality 61 [direct]
  70. Insights [direct]
  71. Bug [direct]
  72. 43-x-y [direct]
  73. bug 🪲 [direct]
  74. platform/macOS [direct]
  75. regrlomon [direct]
  76. Contributing Guidelines [direct]
  77. Code of Conduct [direct]
  78. issue tracker [direct]
  79. Sign up for free [direct]
  80. Sign in to comment [direct]