Fix crash:23193f541b449918 This CL prevents a crash caused by dereferencing a null `WeakPtr` in `CreditCardRiskBasedAuthenticator::OnUnmaskCancelled`. The crash occurs when `OnUnmaskCancelled` is called after the `Requester` object (e.g., `CreditCardAccessManager`) has been deallocated, which can happen during the dismissal flow of UI elements like the Autofill progress dialog. The `requester_` member is a `base::WeakPtr`, and accessing it after the target is destroyed leads to a use-after-free. The fix adds a check to ensure the `requester_` `WeakPtr` is still valid before dereferencing it to call `OnRiskBasedAuthenticationResponseReceived`. This prevents the crash by avoiding the call on a dangling pointer. This issue was observed in crash report crash/23193f541b449918. Bug: 446729816 Change-Id: I271a780a5c7b0653300e60c08bd7d1525248fd0a Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6967944 Reviewed-by: Siyu An <siyua@chromium.org> Reviewed-by: Tommy Martino <tmartino@chromium.org> Commit-Queue: Yiwen Qian <yiwenqian@google.com> Cr-Commit-Position: refs/heads/main@{#1519572}
diff --git a/components/autofill/core/browser/payments/credit_card_risk_based_authenticator.cc b/components/autofill/core/browser/payments/credit_card_risk_based_authenticator.cc index 6b483c5..d7f9dcb 100644 --- a/components/autofill/core/browser/payments/credit_card_risk_based_authenticator.cc +++ b/components/autofill/core/browser/payments/credit_card_risk_based_authenticator.cc
@@ -216,10 +216,11 @@ autofill_metrics::LogRiskBasedAuthResult( CreditCard::RecordType::kMaskedServerCard, autofill_metrics::RiskBasedAuthEvent::kAuthenticationCancelled); - - requester_->OnRiskBasedAuthenticationResponseReceived( - RiskBasedAuthenticationResponse().with_result( - RiskBasedAuthenticationResponse::Result::kAuthenticationCancelled)); + if (requester_) { + requester_->OnRiskBasedAuthenticationResponseReceived( + RiskBasedAuthenticationResponse().with_result( + RiskBasedAuthenticationResponse::Result::kAuthenticationCancelled)); + } Reset(); }