Earlier quoted context omitted.
Chrome isn't your average application, though - it pioneered the modern use of tight process sandboxes in general (in client-side applications, anyway), and in particular was the biggest motivating client for (and Kees Cook on Chrome OS Security wrote some of the code for) seccomp-bpf, the ~3-year-old sandboxing mechanism that allows precise control of permitted syscalls and syscall arguments. The incompatibility her…
Chrome did? IE7 shipped with pretty tight sandboxing in 2006 — and Chrome was only announced in 2008!
http://www.cvedetails.com/product/9900/Microsoft-Internet-Ex...
http://www.cvedetails.com/product/15031/Google-Chrome.html?v...