The site has to request permission to access a device, then the user has to select the device from a permission dialog to grant access.
Good; that's way better than being able to reflash your PS4 controllers with a drive-by.
it does ask for permission, but a malicious website could ask it for a valid reason and then brick it, yup.
On the other side, a controller should not be brickable via HID commands...