I’m not convinced because many of those “legitimate websites” don’t have a very good track record of respecting user security and privacy. Given past events, I find it hard to believe that the ad industry or the entertainment industry or any other industry won’t abuse access to these APIs. To make it worse, if popular websites wants permission to use these highly-invasive APIs, users would have no choice but to cave in. This worries me a lot.
Even if you don’t consider bad intentions, the security implications are huge. Imagine if Zoom had used this feature. The security fiasco a few months back would’ve been made a whole lot worse.