Vulnerable Systems:
* Chrome 25.0.1364.126
* WebKitGTK+ 1.10.2 and prior
WebKit contains a use-after-free error in the 'addChildNodesToDeletionQueue' function [WebCore/dom/ContainerNodeAlgorithms.h] that is triggered when handling SVG animations as a container node may have an invalid first child. With a specially crafted SVG file, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.