's stores meta-data separated from the memory returned to the caller, making it harder to use heap overflows to achieve code injection and execution. See e.g. … and references. Having malloc meta-data near program data is dangerous!

