vulns.co
/
GKData.io MCP

Chromium Project · 1 min read

Chromium Rule of Two: input trust, memory safety and privilege

An architecture policy for avoiding the combination of untrusted input, memory-unsafe implementation and high privilege. It explains safer parsing, privilege separation and careful review of unsafe code behind safe interfaces.

Open the reference Architecture GuideReviewed 2026-10-02

How to use this reference

For an owned component, map input origin, language guarantees and execution privilege. Keep semantic authorization separate from successful parsing.

Before reading

  • Basic understanding of parsing, process privileges and memory lifetime

Context and limits

  • Memory safety does not establish data trust or permission to perform an operation.
  • Chromium-specific exceptions are not blanket guarantees for other projects.

Related visual models

Sources and provenance

  1. The Rule Of 2 Chromium Project · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software