And at that point you can proceed with the same kinds of kernel/driver exploits.
https://web.dev/usb/#get-access-to-usb-devices
However I suppose that the mere existence of this API means that there could be a way to bypass the request; The browser already does have full access to every device.
I've used a web page to run ADB commands to quickly debloat my phone, so I don't see why fastboot support wouldn't work.
There's even a tool to flash your Android phone through the browser (https://pixelrepair.withgoogle.com/ I believe). Adding "automated LineageOS installer through WebUSB" to my infinitely growing to-do list :)
Do you know of any specific risks when flashing devices w/ WebUSB as opposed to the 'normal' way?
With non-Google devices... these might run into problems when the device expects a certain response latency or minimum bandwidth. YMMV I'd say.