Some of these APIs are not overridable inside javascript - overriding is pretty much the only way this can be prevented - short of browser features like CSP and FP. This needs to be the first thing that happens, but there's no standard api to run on your browser to do that, so things have flaws.
A static analysis is often relatively easy to circumvent, something like base64Decode(encodedMaliciousScript) can by-pass them.
Google does various runtime/dynamic analysis to figure out issues, but scripts can do interesting things to circumvent those too (like targeting specific devices through user agent and so on).
It's an arms race, often, where google catches up pretty fast, but bad actors move faster.
Feature Policy check addresses these but ad system and chrome features don't always move at the same speed, and often time there are trade offs that needs to be addressed first before it can be widely deployed.