Thank you. I can see your point and I agree. I only disagree with the argument that it isn’t a (sort of) DoS because JS is allowed to do it. I mean most actual DoS attacks are utilizing perfectly normal behaviors, but simply in abnormal volumes - which seems to be a point here.
Not sure what you mean by OS-level. It crashed a browser which is really easy to do, especially with:
This is where things got weird, Google’s code was allocating 20000 variables in a single frame.
It’s pretty much a DoS at this point.
Isn’t having the mark part of the flex?