Let's presume it is malicious, and the mere act of downloading the WASM starts an injection.
Let's presume it is malicious, and the mere act of downloading the WASM starts an injection.
1. load the site in an incognito tab
2. disable internet
3. run the conversion and download the result
4. close the incognito tab
5. re-connect the internet
In Firefox this is not possible (per tab), but at least you can set the entire browser to offline mode by clicking "File -> Work Offline"
I haven't spent a huge amount of time in the browser security space, but I do think there is quite alot of surface area if you give the browser session sensitive data.
You're right though in general, that's why the incognito tab is important.
In any event, it's an unrealistic attack vector. No bad actor is going to target 0.1% of edge cases when you could get enough damaging information from people who do not go through this process and remain connected to the internet.