If you visit a page that uses touch events and trigger a navigation whilst your finger is still pressed down (and that causes the Node's of the old page to be deleted) then when you lift your finger on the new page we take the old (now dangling) node ptr from the m_originatingTouchPointsTargets map and try to ref it in the Touch constructor which causes a crash. The fix is to empty the map when the event handlers are cleared. Patch and layout test to follow.
Created attachment 55011 [details] Proposed patch and test. Proposed patch.
Created attachment 55012 [details] Proposed patch and test. Change comments in the test slightly.
Comment on attachment 55012 [details] Proposed patch and test. Clearing flags on attachment: 55012 Committed r58760: <http://trac.webkit.org/changeset/58760>
All reviewed patches have been landed. Closing bug.