I just tested it on a Samsung Galaxy S3, in several forms (as src in link, script, img, video and object elements, as well as the href in an a element). Nothing happened here.
http://www.androidcentral.com/major-security-vulnerability-s...
Edit: Found some postings on xda-dev that the GS3 is vulnerable. Could depend on firmware version, I know a system update came out recently on Sprint.