High-performance JavaScript engines such as V8 remain a relevant frontier for security research. This talk will provide an overview of the state of modern JS engine security, covering the evolving attack surface, the current state of defensive technologies, and the impact of new research methodologies. We will start by analyzing the current vulnerability landscape, examining how bug classes have evolved in recent years and highlighting recent trends and persistent challenges. From there we will discuss why traditional memory safety technologies often fail to live up to their promise in this domain, which then leads us to explore more tailored approaches like the V8 Sandbox. We will dive into its architecture, discuss its strengths and weaknesses and conclude with an outlook for its future. Finally, we will look at some recent vulnerabilities, discuss how they were discovered and explore how they can be exploited.