by jcb (Vicar) on Jun 30, 2020 at 02:20 UTC

    Then provide some counterexamples. Even Internet Explorer (as far as I know, the only browser to ever be exploitable with only plain HTML) had those problems only in the late 1990s. All of the recent exploits I remember off the top of my head have been JavaScript JIT bugs.

      Just dog piling IE: it was exploitable at one time or another in every conceivable way, including a character set attack.