I think it’s time to recognize that the web browser engine needs to be a trusted, hardened system-level component to protect user security: these engines deals directly with executing untrusted code being served from potential attackers.
The entire compiler and language-runtime using a JIT becomes an attack surface. Securing Javascript is hard enough.