http://secunia.com/advisories/39925/The vulnerability is caused due to the "window.onerror" handler being allowed to read the destination URL of a redirection. This can be exploited to e.g. disclose session-specific query parameters contained in a target URL by referencing a redirecting site via an HTML "<script>" tag.
The vulnerability is confirmed in version 3.6.3 and 3.5.9. Other versions may also be affected.
Solution
Do not browse untrusted sites while accessing other sites with potentially sensitive information in the URL.