What?!
Modern browser security has gotten orders of magnitude better since Shockwave Flash was removed from web browsers. The sheer unending volume of security vulnerabilities flash introduced into browsers was staggering. Flash (until very near the end of its life) had no sandboxing, and had its own update mechanism. It was the norm for people to be running old versions of flash with unpatched security holes. And flash had so many vulnerabilities - if memory serves, flash generally fielded more CVEs in any given year than the entire rest of the browser!
Remember how revolutionary pwn2own was? "Wow, find a vulnerability and win $1000!". These days vulnerabilities of that magnitude are worth way more money, because of how secure the browser environment has become. ($100k-$1M on the black market as I understand it.)
The only reason it feels like security hasn't improved much is because crypto ransomware has made hacking so much more profitable. But even then, most randomware doesn't usually take advantage of security vulnerabilities in web browsers. Its really quite remarkable how secure the modern web has become; and that wouldn't have been possible if flash were still around.