I guess that's why the JavaScript type confusion fixed in 67.0.3 was "exploited in the wild"? Because on its own, the rendering/JS process is compromised (which of course is bad) but it should still be sandboxed from the rest of the system assuming no sandbox escapes (like this one) are known?