I'll let someone else rant about browser Javascript encryption (it serves essentially no security purpose), but instead just comment to say that "AES-256 in CBC mode" is not a confidence-inspiring description of a cryptosystem.
Have you published the Javascript code you used for this anywhere? Can we see it? I was going to peek at it, but would apparently need to register for the site to do that.
You might consider hoisting your SJCL crypto code out of the DOM and sticking it in a Chrome extension.