❌

Normal view

Received β€” 20 August 2026 ⏭ /r/netsec - Information Security News & Discussion

I escaped the WebAssembly's sandbox and got arbitrary shell execution on the host.

As per WABT's SECURITY.txt, #2831 issue exists

For context:

WABT is a Binary Toolkit for WebAssembly developed by WebAssembly.org (W3C)

wasm2c is a tool inside of it, which is used by many projects like FireFox (via RLBox) to compile wasm down to a sandboxed c library, the assumption is the built C code preserves all WebAssembly's sandbox security features.

This PoC demonstrates escaping that sandbox.

submitted by /u/trustsigRobert
[link] [comments]
❌