Neither is a browser runtime. I would even say running code in a browser could be more dangerous, because you have a huge complexity (HTML+JS+Network Stack+3D Engine+kichen sink in modern browsers) and thus a large attack surface. Whereas if you built an isolation layer around a OS process (or bytecode), you can restrict the code to do only what it has to (render to audio and video buffers), and you have to audit the wrapper (sandbox/VM/runtime), which is much smaller than the whole browser.
The reason browsers are relatively safe now is that so many brilliant people are working really hard on them, not because they are inherently safe.