> But researchers found that the bug could allow malicious JavaScript to run outside of the browser on the host computer.
The phrasing may unfortunately mislead the less technical readers of their audience.
JavaScript always runs “on the host computer”, this should be described as a sandbox escape.