I don't really know if this is actually known, but I thought it was worth writing.
In a few words:
While other browsers do not allow particular charaters in sub domains, IE does. Hence it's possible to abuse that behavior to exploit referrer based DOM Xss.
..continue reading on Minded Security