More importantly, it's trivial for an adversary who cares.
If I'm encrypting a note containing state secrets to send to a foreign intelligence officer, the NSA has the technology (and more importantly, the resources) to brute force their way in.
And if your password is too complex to crack (read: a 256-bit key), you probably can't remember it either, which means you have to write it down somewhere; so an adversary who cares would find an outside channel (subpoena, hack your personal computer) to determine your key.
What is your key derivation algorithm? PBKDF2?
Your point about weak passwords holds in both ordinary clients and in the browser. It's just a matter of degree. There are plenty of sufficiently strong passwords that are memorable. Since the degree of weakness tolerable is logarithmically proportional to the hashing time and JS is usually within an order of magnitude of native code, the additional entropy required is small given equivalent hashing time.