CFXMLParser 7-Byte Crasher
// "<a>" in UTF-16 LE + a single dangling byte const UInt8 bytes[] = {'<', 0, 'a', 0, '>', 0, 'X'};[…]
The whole bug is a confusion between bytes left versus UTF-16 characters left. The result is repeated buffer doubling until allocation fails, and a local process crash if the exception is uncaught.