To be fair, exploiting games and emulators directly aren't a particularly common attack vector. I've never heard of any wild malware that attempted to exec itself via a (legit) emulator, although IIRC arbitrary code exec on clients had popped up a few times in the wild on older multiplayer games (mostly CoD and various Source multiplayer games). Most of the "malware" stuff related to emulators I've heard of are cheap tricks (e.g. tainted emulator binaries on shady websites, EXE files deceptively labeled as ROMs) and not any fancy exploits.
Attacking emulators through games for code execution however is fairly novel
https://www.nccgroup.trust/uk/about-us/newsroom-and-events/b...
http://publications.lib.chalmers.se/records/fulltext/238600/...