Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
https://code.google.com/p/v8/source/detail?r=20138
https://code.google.com/p/chromium/issues/detail?id=354123
http://www.debian.org/security/2014/dsa-2905
http://security.gentoo.org/glsa/glsa-201408-16.xml
http://lists.opensuse.org/opensuse-updates/2014-05/msg00012.html
http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html