If the attacker controls the instruction stream it's game over (since they can disable the mask), but if they're just writing wasm that generates malicious speculative in process loads, it would prevent that.
Then an attack would have to trick library calls in to doing the same job, which is certainly possible, but much harder.
Of course this would negate many of the benefits of staying in the same process, so I'm not necessarily saying it's a good idea.