Chrome has probably invested > 1 billion dollars into their codebase at this point. Certainly >100million into security.
They sandbox their code aggressively. They build this project with security in mind from day 1 - it's been architected for it.
The Chrome security team(s) has a lot of power for a product security org.
They fuzz. They invent new fuzzers. They cluster their fuzzers.
They have a world class bounty program.
They have a world class research team for finding vulns.
They invent or otherwise aggressively adopt mitigation techniques.
But someone out there did it.
Their track record for security is something to really be proud of - this is the first public ITW exploit of its type that I am aware of. But users are getting owned because of, at the very least, a Use After Free vulnerability.
Let's just collectively admit it, finally - you can't write safe C++ in a codebase this complex.
edit: (From a post below)
To be clear, I'm not saying "Chrome should be rewritten in a memory safe language", I'm saying that Chrome is an excellent project to point to, say "Wow, no one does as much to secure a codebase as them", and to follow that up with "and they still got owned by UAF".