Isn't the main issue with e2ee on the web the fact that you're battling on three fronts?
1. You need to securely get the code and resources to the browser. A state level attacker can make this very hard.
2. You need to securely run the code on the client which may or may not include code from n-third parties.
3. You need to securely handle data and logic from the client which may or may not involve n-third parties.
Phew. That's a heck of a challenge.