Here are a bunch of great real-life examples from the Playstation 4 hacking scene: https://www.psdevwiki.com/ps4/Working_Exploits
Or iOS exploit chains, some of which I've used intentionally as part of iOS jailbreak tools like unc0ver. From Project Zero's "very deep dive into iOS Exploit chains found in the wild": "Earlier this year Google's Threat Analysis Group (TAG) discovered a small collection of hacked websites. The hacked sites were being used in indiscriminate watering hole attacks against their visitors, using iPhone 0-day." https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...
I imagine the real-world application of this MSI thing is something like:
1) Get silently-malicious MSI on to target machine (via download server compromise, poisoned non-TLS download, redirect TLS-downgrade, etc etc)
2) Got malicious "trigger" exploit code on to any web page used by the target (via web server compromise, weak human security like admin passwords, etc etc).
3) There is no step three.
With this in mind we can look at even very recent real-world news—like the simultaneous patching of five Chrome exploits in June 2020—and instantly see how it's not just hypothetical: https://www.cisecurity.org/advisory/multiple-vulnerabilities...
For example, one of them (CVE-2020-6493) is "Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page". How many more of these do you think are hanging around out there, waiting for Google to get the 'okay' to fix?