That is wrong (from the EME standard[0], section 10):
> User Agent and Key System implementations MUST consider media data, Initialization Data, data passed to update(), licenses, key data, and all other data provided by the application as untrusted content and potential attack vectors. They MUST use appropriate safeguards to mitigate any associated threats and take care to safely parse, decrypt, etc. such data. User Agents SHOULD validate data before passing it to the CDM.
That is, a browser has to be secure to implement the EME standard, if it is not secure it is not in compliance with EME! (Next up, anybody who falls from a building is in violation of the W3C gravity standard and as such flying is possible.)
I trust I don't have to point out that I am joking.