They essentially can via the WebRTC api, albeit in a more cumbersome way. There's nothing inherently insecure about it and the onus rests on the serving party and the browser itself to ensure no foul play is happening.
http://www.adobe.com/devnet/articles/crossdomain_policy_file...
Only Flash actually has an API like BSD sockets where you can do make TCP connection and send an arbitrary protocol over it. Hence, since they want to test protocol compatibility, they used Flash. Doubtless if Flash didn't exist they would provide a handy Python program or something, and 99% of visitors would never run it.