Processing maliciously crafted web content may lead to a cross site scripting attack. This issue was addressed with improved checks
This is an iOS CVE ("Prioritize text/plain content type over suggested xhtml MIME type"). It doesn't affect WebKitGTK.