In 2024, V8 introduced a lightweight in-process sandbox designed to confine arbitrary memory corruption. Two years later, it is time for a technical reality check on its architecture, dissecting how subtle implementation compromises and compiler optimizations led to practical sandbox escapes. Beyond containment, vulnerability discovery is currently undergoing a paradigm shift with the rapid progress of LLMs. We share empirical research comparing traditional fuzzing approaches against new LLM-powered vulnerability discovery agents to evaluate the actual overlap between the two. Finally, we close with an outlook on where browser security may be heading in the future.
Michael has been working on the V8 JavaScript and WebAssembly virtual machine at Google since 2015. He now leads the V8 Security team with a focus novel security features and architecture to eliminate and contain memory safety issues. Before that he worked on memory management in general and garbage collection specifically.
Samuel works as security researcher on Google's Project Zero, focusing on browser-based and 0-click attacks. He previously led the V8 Security Team from 2022 to 2025, developing innovative security features for the V8 JavaScript Engine with his team. Now back on Project Zero, he also contributes to the Big Sleep project. Before joining Google in 2019, he was an independent security researcher who participated in pwn2own and published two Phrack articles on JavaScript engine exploitation.