That's interesting. Apparently, the __defineSetter__ call is still valid in Chrome.
Example http://jsfiddle.net/V53BL
Example http://jsfiddle.net/V53BL
<script>
Object.prototype.__defineSetter__('user', function(obj){alert('Hijacked!');console.log('Hijacked!', obj)});
var trigger = [{"user":{}}];
</script>
<script id='current-user' src="http://my.secretapi.com/users/current"></script>
Where the API returns something like [{'user':{'name':'Joe Bloggs'}}]
(Un)Fortunately (depending on which side of this you're on...) they've plugged the holes?var x = [{"user":"dude"}]; This won't trigger, and this is what the script include tag executes via the response.
x.user = "wow"; This will trigger, however.