parser is in javascript (google docs), in a sandboxed browser (chrome), in a system whose root partition is read-only, and hash-verified each boot and whose bootloader is in a physically-write-protected SPI chip.
good luck :)
good luck :)
And you don't need to persist anything to disk, just get a key logger going in memory. Or scrape the data from your other processes. Once you get arbitrary code execution on the machine it's game over.
Seriously, I deal with this kind of stuff for a living. No one is immune to these kinds of attacks; not you, not me, not anyone.
Feel free to submit your function exploits that you say are so easy to make