4 ms·
From what I saw that's just about exploiting WASM memory within the sandbox - like they say "at wrost WASM can make a mess of it's own memory" and they show som
by reader_mode 5y ago
From what I saw that's just about exploiting WASM memory within the sandbox - like they say "at wrost WASM can make a mess of it's own memory" and they show some implications of that. That's mildly interesting to me, you still need to go through DOM to do anything system related - you can't just read random files off of disk or use some system API to exploit other parts of the system. If API security is broken for WASM it's broken for JS as well. That's completely different from having a separate sandbox running as a native extension.