Am I right that this makes the tradeoff of removing the possibility for vulnerabilities in specific web applications, but creates the (admittedly slimmer) chance for Universal-ish XSS in browsers?
Browsers have a track record of being able to ship security bugs for severe issues within a day or two. Compare that to patching every individual website.