I wondered the same thing years ago. I always thought that browsers would have implemented other security measures so that websites avoid doing this.
Around 90 something percent of websites I visit don't implement that `for(;;)` or `while(1)` solution.
So are we saying that they're vulnerable sites?