Update, you can read more about these particular errors in general and in Google Chrome now here: https://forum.avast.com/index.php?topic=205727.msg1409362#msg1409362
Also see the dangers for XSS Bypass vuln.: https://forum.avast.com/index.php?topic=205727.msg1409362#msg1409362
allthough there should be other insecure conditions for this to make XSS feasible, like no “same-orgin” rule maintained,
no sri-hashes being generated or no HSTS header being implemented on website.
polonus (volunteer website security analyst and website error-hunter)