Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 9d7f61d1374e4491915d3ec83be36e434d18a1aa
      
https://github.com/WebKit/WebKit/commit/9d7f61d1374e4491915d3ec83be36e434d18a1aa
  Author: Andy Estes <[email protected]>
  Date:   2026-09-28 (Mon, 28 Sep 2026)

  Changed paths:
    M Source/WebKit/Platform/ios/WKAVContentSource.mm

  Log Message:
  -----------
  [iOS] Crash when accessing -[WKAVContentSource currentAudioOption] after 
audio options change
https://bugs.webkit.org/show_bug.cgi?id=325517
rdar://187730234

Reviewed by Eric Carlson.

When PlaybackSessionInterfaceAVKit::audioMediaSelectionOptionsChanged is 
called, the audio options
array and selected index are changed on WKAVContentSource via two separate 
calls (-setAudioOptions:
and -setCurrentAudioOptionIndex:). If a client of WKAVContentSource observes 
-audioOptions and then
synchronously calls -currentAudioOption in response, the value returned by 
-currentAudioOption will
be based on a stale index. While this fundamental issue is unavoidable given 
the current design, we
should at least avoid NSRangeExceptions being thrown due to the stale index 
being outside the
bounds of the array.

While we have evidence of this exception being thrown for -currentAudioOption, 
the same pattern is
used in -currentAudioDescriptionOption and -currentLegibleOption, so this fixes 
all three places.

* Source/WebKit/Platform/ios/WKAVContentSource.mm:
(-[WKAVContentSource currentAudioOption]):
(-[WKAVContentSource currentAudioDescriptionOption]):
(-[WKAVContentSource currentLegibleOption]):

Canonical link: https://commits.webkit.org/322098@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to