"possible to violate browser cross-domain restrictions"
Sounds serious .... wonder what it means tho

Did they really find a security hole, that did not include MS