I know it's an unpopular opinion, but I actually miss the days where webpages were static and did not need JS to load basic functionality.
With the rise of the IoT, security is only going to be more and more difficult (e.g., all the automanufacturers' issues as of late); here's hoping we can figure out a way to make security mainstream…
Try telling that to people who want them to do more. No one wants to download and install your desktop app - it's too much work and people are too concerned about security. Mobile app stores are much better at minimizing that friction which is why native applications are so popular on that platform... but there's still friction.
The web is awesome because it's so easily accessible. And people want to do sophisticated things easily - they don't want to mess with downloading and installing stuff.
The fact that the web started off a certain way and browsers are called "browsers" has literally zero impact on what people demand from their technology. What they want now is for their browsers to solve problems. So that's what people make.
To me browsing would include all the JS stuff we have now plus all kinds of things we haven't dreamed up yet. Call me old fashioned but I'm all for continuing to move the web forward.
There will be vulnerabilities in native apps, there will be vulnerabilities in web apps or, put more simply, there will be vulnerabilities.
Patch 'em up and charge ahead.
I'm all for less bloat, and I can't figure why would a browser double as a PDF reader, for instance, when a native app is invariably faster, more feature-rich, more customisable and more secure. However, it's difficult to draw a concrete line between plain browsing and web apps.
A native app is less secure. They're all written in memory-unsafe languages, are not guaranteed to be up-to-date, and do not run sandboxed. Integrating a JS PDF viewer into the browser hurts performance, but it's more convenient (no separate app to open, can start reading before it finishes downloading), and much less likely to be a security risk.
So how can we even trust the browser if native apps are always less secure according to you?
The exploit ran despite the sandbox if I understood it right.
Mobile is a different story of course, but also not portable.
In short I'm not sure what you're suggesting.