Basically, a website could download your entire Gmail contact list by adding a bit of code to their server and exploiting Google’s JSON API. The problem has apparently been fixed, very soon after the vulnerability was found.
Via | Techcrunch.com