The crash is not immediate, but there are actually two ways to trigger it and I believe they are separate problems.
The following will cause Safari to crash with =93Access violation reading =94.
Whereas these will crash Safari with =93Access violation writing to [BBADBEEF]=94
* Develop->Show Error Console (Unreliable)
* Develop->Show Web Inspector (Unreliable)
* (Right Click)->Inspect Element
I can=92t seem to affect any registers in an advantageous way but I do see several pointers to \x41 blocks on the stack. At least you could put shellcode in these and jump to them if you could control EIP. If anyone is able to do anything with this, please let me know.