They already are partly in JS so there's a smooth path.
(Wasm isn't safe but could be a building block too)
(Wasm isn't safe but could be a building block too)
Not sure why you think that WASM is less secure than JS though. Even if the WASM heap has internal corruption there's no way for this to do damage outside the WASM sandbox that wouldn't be possible in JS.
Was it this one? https://hacks.mozilla.org/2021/12/webassembly-and-back-again...
Or perhaps this one? https://hacks.mozilla.org/2020/02/securing-firefox-with-weba...
java applets promised a sandbox and then we had years of continuous vulnerabilities of escaping said sandbox.
And also we'll pay for a bypass of the wasm sandbox. (Actually, looking at our table, I'm going to try and get the bountyamount upped...)