1) increases the attack-surface[0] of the browser (arbitrary code execution in victims browser)
2) wasm shares some of the same vulnerability classes from native applications (thanks to code generation frameworks that allows you to spit out wasm in addition to say C - see Nim & others offering generation via llvm backend)
3) cryptographic verification of payloads is still not possible (afaik)
4) binary blobs from untrusted sources which isn't auditable in the way javascript is (raises the bar for security researchers to identify malicious payload, or really just anyone who want's to audit / poke around)
5) thanks to 1+2 wasm shares the same pitfalls as JavaScript when doing crypto in the browser.
6) all of the above works over plain HTTP links (hurray)
7) assumes that security/integrity can be derived from language subsets and a few rules to prevent specific type of behavior[1]
[0] https://i.blackhat.com/us-18/Thu-August-9/us-18-Lukasiewicz-...
[1] https://webassembly.org/docs/security/
[2] https://nvd.nist.gov/vuln/search/results?form_type=Basic&res...
edit: link to current CVE's