Each website is rendered in a separate process with a sandbox, each with an empty chroot + process namespace + network namespace + tiny seccomp-bpf + syscall whitelist.
Chrome also has a stronger sandbox, pioneers better SSL, supports PIE on binaries, uses pepper - doesnt use native Flash plugins, the JIT compiler does randomization / encryption tricks to make it hard to heap spray exploit code. They have their own hardened memory allocator called PartitionAlloc.
Etc Etc.
Firefox also had more critical CVEs in 2014 than Chrome: http://pastebin.com/raw.php?i=2CRyJkmV
And reports of sandbox escapes are less common in Chrome for a reason.
For my own use cases, Chrome drags my whole system performance into a gutter and shoots it full of bullets.
In other words, it’s not just a “trade-off”, but rather Chrome is completely and utterly unusable, while both Safari and Firefox handle the load with no problem.
However, my high memory consumption in Chrome was due to using AdBlock, which is much lower now that I switched to uBlock. Even back with AdBlock, memory was never an issue with many tabs open.
My only problem (which is probably not Chrome's, but my laptop's fault) is that sometimes, when having ~20 tabs open, and certain tabs are idle for a long time, they take a bit of time to re-render once I visit them again, but that also used to happen in Firefox.
I really don't know what you're talking about - Chrome is a dog after ~10 tabs are opened, uses crazy memory and becomes unusable fast once it starts paging. Firefox remains stable, backgrounds tabs you're not using in a graceful way, and doesn't try to open and render every single tab at once on a session restore.
It's unbelievable that Chrome still does this, after the problem has been reported for years.
That's the thing with anecdotal evidence, it's a sample of one.
There are WebKit-based browsers far lighter and faster than Firefox. Chrome, Firefox in Linux, and the Tor browser provide better security. Isolating browsers in separate VMs or Qubes AppVMs provides even better security.
Sure, its process model isnt as "secure" as chrome since it has the trade off or sharing more memory among other examples. But as a user, it seems like a freaking good enough trade off right now....
Here's an old paper that talks about the architecture (it hasn't changed much at a high level):
http://seclab.stanford.edu/websec/chromium/chromium-security...