Greetings Jan – thank you for your rapid response.
Generally speaking the answer is “no”.
Where I am puzzled is that the code changes for this patch appear to be in the core browser for those 3.x versions, and because the 4/21 security release just 6 days before was pushed out to these versions right away.
For what it’s worth, I think it’d be good for security release announcements to explicitly say which (x.x) versions will be patched, and “all others will not receive a patch.”
I think this is especially important, as the auto-update process for versions >= 3.7 can lead to a feeling of security that those auto-update-capable versions will be updated.