Are there any plans to sandbox the content handling (e.g. HTML parsing and image loading) in a separate process to mitigate e.g. memory-safety issues and other security problems?
Firefox [1] and Chrome [2] use seccomp-bpf and various other Linux-specific APIs to implement their sandboxes. FreeBSD provides Capsicum [3] for this, but it's not supported by Firefox or Chrome.
Maybe Dillo could use the newer Landlock API [4] on Linux, which is being evaluated [5] for Chrome. This API seems more similar to Capsicum, so it might make it easier to support FreeBSD as well.
[1] https://wiki.mozilla.org/Security/Sandbox
[2] https://chromium.googlesource.com/chromium/src/+/refs/heads/...
[3] https://wiki.freebsd.org/Capsicum