Sure it does. Execution is a permission you can set in the security tab.
> a rename could make it runnable
This is more likely why.
This much I understand - but why can something so tightly integrated into the OS not instead intercept a file rename event and scan at that point?
I seem to be lacking sufficient information as to what specifically about Windows necessitates scanning everything on the filesystem when macOS and the various common Linux distros seem to do fine without it. It's not as if Windows is the only OS with interpreters, either.
Is it really just that Windows users download and run random junk? It's been so long that I've seen a virus of any kind anywhere at all that I genuinely have no clue how people become infected with them or indeed whether it still really happens at all.
It certainly feels to me that the era of random toolbars and clearly visible desktop malware is over, but at the same time I live in a different bubble than in the past.
I'm a bit late to the conversation, but can confirm that yes, people do still get infected.
We almost always turn something up while doing virus scans at the repair shop I work at, and we mostly use off the shelf products, along with a couple other tricks.
While I agree the overhead is atrocious, buffer overflows and similar bugs can turn an "innocent" non-executable file into an executable, like this[1] JPEG file parser issue affecting a large number of applications using GDI+.
That said, I'd be surprised if it couldn't be smarter about this.
[1]: https://us-cert.cisa.gov/ncas/archives/alerts/TA04-260A