Code injection like this is why we have historically been unable to enable stronger process mitigations for Chrome that might improve security and stability. It's a real pity :(
https://bugs.chromium.org/p/chromium/issues/detail?id=851565...
The flag we (still) can't enable by default is
--enable-features=BrowserDynamicCodeDisabled