4 ms·
If WebAssembly is running in the browser, it’s not calling into C/C++ modules. If WebAssembly isn’t running in the browser, it doesn’t need to be sandboxed. T
by zeroimpl 7y ago
If WebAssembly is running in the browser, it’s not calling into C/C++ modules.
If WebAssembly isn’t running in the browser, it doesn’t need to be sandboxed.
Thus I don’t think we need to be concerned over WASI sand boxing in the same way as applets.
- pjmlp 7y agoIf JavaScript is calling into WebAssembly modules compiled from C and C++, naturally do we have to care about security. The existing model does not prevent exploits taking advantage of internal memory corruption inside the sandbox.