You don’t understand how WebAssembly works. You severely misunderstand how the VM secures itself. Listen to what all the other comments are trying to teach you. There are no security vulnerabilities in your code.
For simplicity, pretend any pointer dereference is a function call with the address as its argument. The VM makes sure it’s within the range of valid values every time. There is no executable code in that range either, only data. Further, function pointers are not real pointers, just an index into a table which again, is checked on any indirect function call.
In practice the memory is secured by allocating a 4 GiB aligned memory range and just masking off the pointer on every access so it’s within that memory. This way there’s very little to no overhead, depending on the architecture.