Since it won't be native code, they'll only be able to abuse a FF bug exposed by the JS plugin API, but should be in a very bad position to exploit a kernel bug...
Same process isolation, but the JS plugin got a vastly reduced surface to attack.
Same process isolation, but the JS plugin got a vastly reduced surface to attack.