This is a tracking bug for a project to store content-controlled buffers such as strings, ArrayBuffer, network buffers, and other similar data in a heap separate from the normal C++ heap.

Links and prior art:
As we move this forward I wanted to point to the current partitions that Chromium has:

The first target would be what they call the buffer partition - all Javascript objects that are near-entirely user controlled (strings, arrays, and any similar or synonymous types) would be segmented into a separate partition. Once that is done and baked we can determine what would be good future targets for this work.
