It has same downside as WASM. Running precompiled bytecode is a bad for security as it always been. It was no more than a year when a remotely exploitable WASM hole was exposed (derivatives of Spectre and co.) Knowledgeable people told that ISA level hole that can be exploited remotely over the web will be "a one minute global IT disaster" if somebody would resort to propagating it through a big adnet or paid traffic…
Weren't Meltdown/Spectre exploitable via Javascript?
Re: Feasibility of low-level GPU access on the Web
#131Actually, the POC required both sharedbuffer object and ASM js (actually an even worse thing than a bytecode)