WASM Security Sandboxing

Discussions debate WebAssembly's sandboxing capabilities, security model compared to JavaScript and native code, and potential for exploits or safe untrusted code execution.

📉 Falling 0.4x Security
2,545
Comments
17
Years Active
5
Top Authors
#1324
Topic ID

Activity Over Time

2010
2
2011
1
2012
2
2013
2
2014
2
2015
15
2016
26
2017
125
2018
243
2019
273
2020
245
2021
313
2022
397
2023
378
2024
229
2025
267
2026
25

Keywords

XSRF PHP JS ASM bytecodealliance.org WebAssembly E2E wasmtime.dev WASM JVM wasm webassembly sandbox sandboxed security sandboxing js javascript jvm untrusted

Sample Comments

pjmlp Mar 16, 2022 View on HN

Currently WASM has less security protections than native sandboxes, not more. Read security section of the standard.

devwastaken Sep 9, 2019 View on HN

Wasm is not sandboxed. Wasm is simply another standard way of writing instructions that can be platform independent. Wasm has no standard library software for sandboxing. Sandboxing is entirely dependent upon software implimenting execution of wasm instructions. Very few do this, there are fewer from reputable sources that do it without a JavaScript engine, and none that put sandboxing first.

nynx Sep 9, 2019 View on HN

Wasm is sandboxed. It's designed to be entirely safe to run.

9dev Jul 23, 2025 View on HN

Why would WASM be any less secure than JavaScript?

rini17 Dec 28, 2020 View on HN

WASM only provides sandboxing. That is not the same as security nor it means runtime safety nor protection from undefined behavior.

nicoburns Nov 8, 2018 View on HN

Security. WASM is sandboxed by design.

themerone Oct 7, 2025 View on HN

Wasm can be sandboxed. Its a safe as visiting a website with javascript.

StreamBright Jan 17, 2018 View on HN

What are the security implications of wasm?

modeless Apr 15, 2021 View on HN

That's super cool! Interesting that WASM provides a way to sandbox untrusted code. Did you consider sandboxing JS with iframes as an alternative?

pjmlp Sep 5, 2023 View on HN

WASM offers much less security mechanisms than OS services + containers.