Vulnerable Systems:
* Chrome 25.0.1364.126
* WebKitGTK+ 1.11.5 and prior
WebKit contains a flaw in the 'XSSAuditorDelegate::didBlockScript' function [WebCore/html/parser/XSSAuditorDelegate.cpp] and 'XSSAuditor::filterToken' function [WebCore/html/parser/XSSAuditor.cpp] that is triggered when empty referrers are replaced. This may lead to leakage of potentially sensitive referer information to a context-dependent attacker.