"... I'm completely unwilling to expand my vulnerability from the 'site I opened' to 'every external service they can think to load'."
I think that is a reasonable decision.
What would be the most effective way to protect against this vulnerability?
1. Ask the authors of the major browser you use to please change their software to your benefit instead of the advertisers who pay millions every quarter and finance the authors' salary.
Right now, all major browsers load scripts automatically. No user input required.
What gets loaded is determined by the website, not the user.
2. Turn off Javascript.
3. Use a browser that does not load scripts automatically.
Or use one program to retrieve the stuff you want from the web, e.g., an http client, and another program or programs to read/view/play it, offline. Only the http client needs an internet conection.
4. Stop using the web. (Not meant to be flippant.) The web is but one part of the internet. Alas, it has been largely "taken over" by the lure of the sale of personal information about consumers and advertising.
Look for existing or new internet protocols that do not use the web but which can provide the same things that the web does.
The software to access these protocols does not have to be written by organizations with interests in data collection and advertising.
It may be possible to have a segment of the network that is noncommercial. Free from ad delivery.