The hover-check Glib::signal_timeout re-arms every 50ms and is not owned by the Workspace. Since Workspaces are destroyed at runtime, a workspace removed while its check is armed would let the timeout fire on freed memory (use-after- free, also touching the destroyed m_button). Add a destructor that calls stopHoverCheck() to disconnect the source.