"Let's switch from an email client written in a safe high level language that's also running inside multiple sandboxes and which has a full time security team (e.g. gmail) to ...... a mail client written in C"
Doesn't seem like a great approach.
"Let's switch from an email client written in a safe high level language that's also running inside multiple sandboxes and which has a full time security team (e.g. gmail) to ...... a mail client written in C"
Doesn't seem like a great approach.
Isn't the general premise here that one can choose to package up any program in as many deeply nested (virtual or physical) sandboxes as one would like, but there's an inherent benefit to the piece of software inside all those boxes exposing to one's adversary as few avenues as possible to attempt to escape them (specifically as it pertains to people in the business of painting targets on their backs e.g. Soghoian)?
Put another way, of course Gmail and Chrome have dedicated security teams, but they won't ever have prevent $GIVEN_INFOSEC_RESEARCHER's box from getting owned teams.
The best vector is probably taking control of the IMAP/POP server Mutt is connecting to and finding a vuln that will leak an address back to the server and another vuln that will take control over the instruction pointer.
Or alternatively hope there is some broken shell command injection lurking in Mutt.