Everything looks obvious in hindsight doesn’t it? Several of the organisations you’ve mentioned
have funded projects to rewrite critical internet infrastructure in a memory safe language - HTTP client, HTTP reverse proxy, DNS resolver, NTP server, TLS library, AV1 decoder, a replacement for sudo, among other projects (
https://memorysafety.org). More can always be done, and it can always be done faster than it’s being done.
Fwiw, it’s possible to use zstd instead of xz, which was created at and actively maintained at Facebook.
So if you were expecting Big Tech to identify this class of problem and do something about it, it seems like they are. But if you expected them to eliminate every single possible instance of such an issue, that’s a bit much isn’t it?