Cure53's report details a complete bypass of WebSign as implemented, as well as stern warnings against relying on a non-security feature for security.
Breaking WebSign would require defeating TLS public key pinning (which is a security feature), thanks to the technique that an email I just received so perfectly referred to as "HPKP suicide".