If it's the first one, I dont think i really care.
If it's the first one, I dont think i really care.
But worth adding that Wasm by design lets you statically inspect all the things the Wasm can call. If the Wasm receives access to networking, or eval(), etc., then there is a real risk. However, often the Wasm imports and exports are extremely limited and easy to verify for safety.
Someone who controls the image data can perform an XSS, i.e. steal your credentials for the website, or your credit card info if that's stored server-side. That's not as valuable a target as controlling your computer, but it's not nothing, and can be chained.
This is completely realistic as Figma is full blown image editor written in C++ compiled to WebAssembly :)
https://www.figma.com/blog/webassembly-cut-figmas-load-time-...
If this is the case it mean there is already a hacker or virus running outside the sandbox which mean I already have bigger problem to worry about :).