Source - http://secunia.com/advisories/14820/
The vulnerability is caused due to an error in the JavaScript engine, as a "lambda" replace exposes arbitrary amounts of heap memory after the end of a JavaScript string.
Good call!

Thanks for the info.

Yo!