3 ms·
Doesn't each wasm module get its own isolated memory? If so, then you could only shoot your own sensitive foot.
by CUViper 7y ago
Doesn't each wasm module get its own isolated memory? If so, then you could only shoot your own sensitive foot.
- yellowapple 7y agoThere's no guarantee that the module's memory is strictly isolated; I don't recall what the specification says, but on a technical level there's nothing stopping a WASM implementation from exposing the same memory range to multiple WASM modules (and in fact, I can imagine this to be a very common use case for multiple memories, e.g. defining STDOUT and STDIN as memories shared with other modules, with one module reading and the other writing). Most (all?) WASM runtimes currently enforce this isolation, though, for security reasons. If any do allow memories to be shared between modules, I'd imagine it'd be very explicit and opt-in.
- pjmlp 7y agoThat is already enough to trigger CVE on WASM modules.
- kevingadd 7y agoYes, but a "module" can be an application and a full set of its dependencies. It's unlikely that its dependencies would have isolated heaps, as there would be no way for them to communicate (they can't touch each others' pointers, etc) other than through intermediary JS. So any vulnerability in any piece of wasm in your webpage effectively compromises everything. One compromised module can also likely reach out into the page and then use other modules' public interfaces to compromise them too. There is not sandboxing in place to prevent this sort of attack, the sandbox merely protects the browser from attack by content.