it is interesting that most of the CVEs are "use after free". instead of being stuck in an endless cycle of detection and patching, maybe, it's time we consider better ways...
https://microsoftedge.github.io/edgevr/posts/Super-Duper-Sec...
https://microsoftedge.github.io/edgevr/posts/Introducing-Enh...
What they've found is that JIT can be disabled in most sites with no user-visible impact.
This, combined with WebAssembly, is a game-changer in waiting for browser security.
[1] https://chromium.googlesource.com/chromium/src/+/ddc017f9569...