Section 5.1 gives a good example: an image sharing service that processes images using libpng. This has to be combined with a document.write() of HTML in C, which is realistic.
Someone who controls the image data can perform an XSS, i.e. steal your credentials for the website, or your credit card info if that's stored server-side. That's not as valuable a target as controlling your computer, but it's not nothing, and can be chained.
This is completely realistic as Figma is full blown image editor written in C++ compiled to WebAssembly :)
https://www.figma.com/blog/webassembly-cut-figmas-load-time-...