A mixed scripting vulnerability is caused when a page served over HTTPS loads a script, CSS, or plug-in resource over HTTP. A man-in-the-middle attacker (such as someone on the same wireless network) can typically intercept the HTTP resource load and gain full access to the website loading the resource. Chromium is trialing blocking mixed scripting conditions by default in the first Chromium canary release (14.0.785.0), we are trying to fix the bug.”]
Source: https://security.googleblog.com/2011/06/trying-to-end-mixed-scripting.html