Funny question, basically with corrupted data anything goes.
For a very extreme convoluted example, maybe that value given back to the JavaScript layer will trigger a patient death by sending the wrong value to their insulin device monitor.
But yeah, code and true call stack will be perfectly safe.
Successful lawsuits against insecure software need to become a common event until most companies actually start paying attention to their technology stack and development processes.
You can't overwrite code or the true call stack, so what's the (security) risk?