logoalt Hacker News

fpolingyesterday at 10:58 PM1 replyview on HN

Browsers run it in a sandbox process together with allocator hardening. Most of the bugs then are just crashed of the sandbox

Another option is WASM or WASM-style sandboxes if using another process is undesirable.


Replies

johnnythunderyesterday at 11:11 PM

One chained sandbox escape away from compromise.

show 2 replies