WebKit in Apple Safari before 4.0 does not prevent remote loading of
local Java applets, which allows remote attackers to execute
arbitrary code, gain privileges, or obtain sensitive information via
an APPLET or OBJECT element.
According to https://bugs.gentoo.org/show_bug.cgi?id=287494#c0, this issue was fixed in =net-libs/webkit-gtk-1.1.10. Updating status to [glsa], so it shows up in reports accordingly.
Presumably all affected versions are gone from tree. Closing as discussed with keytoaster. No GLSA for you.