It still is, Nick. People are constantly looking for chinks in everything's armor. the good part is that it is known and there is a way to address it until it is officially sealed.
Javascript can do some amazing stuff, but it can also be used maliciously as we have seen here.