Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



Hum... You are aware that those are one where the attacker gains execution capabilities inside the sandbox and one hardware vulnerability that affects every single language, right?


Gaining execution capabilities inside the sandbox is already good enough to compromise its behaviour, e.g. everyone gets true back when is_admin() gets called.

More devs should get security trainings.


Yes, but it's a complete mischaracterization to claim it's a failure of the sandbox.

On this specific case, it is quite a big deal to add write and execute controls to the WASM memory, so it requires further justification than "I can do stack underflow attacks on my C code". Even though "I can do stack underflow attacks on my C code" is relevant information.


well it's not perfect, no.

my point stands though. WASM is not ActiveX where the whole applet has admin permission on the computer.


In abstract, in practice it depends on which runtime is being used.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: