The web browsers are so much more secure than what we had before (just accepting executable binaries from other people), so I look at this as a way forward.
In this case it's not even an exploit really; more like social engineering. (Tricking users into granting the phishing site unrestricted access to their Yubikey, then using that access to trick the user into authenticating a login session for the phishing site.)
A browser is more secure than Qubes?
The flaw is in legacy software, not in what is possible. Had humanity spent the effort that was spent on browsers on operating systems instead, we'd have had the same security improvements without all the negatives.