Why were we Qt/KDE maintainers put on CC for this bug? This is clearly a Chromium-specific vulnerability that cannot possibly affect QtWebKit or KHTML (because neither supports Pepper plugins). Only QtWebEngine can possibly be affected, but it is not currently in Fedora.