Oddbean new post about | logout
 yeah its slightly more isolated, but its still floating around in the process space and js env. I would just feel more comfortable with runtime.sendNativeMessage to an app with no network access and shared keychain access with Damus 
 makes sense, but you probably have bigger problems if there’s a safari ACE vulnerability