Comment by shuckles
"We will let anyone run arbitrary JavaScript on all your web pages if you send them a referral link" is surely a 6-7 figure vulnerability for a web browser. That this vulnerability was discoverable using about two steps of analysis tools suggests many more issues are in the product.
Not just that - seems like it allowed running privileged JavaScript (full access to your system) on the preferences page as well.