"javascript will run if it is withing the preview of the message" meaning that hackers could grab email addresses or possibly steal cookies and compromise Google accounts. It's surprising that this vulnerability existed and who knows how long this has been a hole.