Bitcoin's cryptologic is open-source; it doesn't have to be secure from tampering in the same way a videogame console has to be secure. A videogame console doesn't want you modifying game code or running your own code on the hardware. Nobody cares what you do to your bitcoin client; you'll just lose your coins in some invalid[1] transaction or maybe you find some amazing flaw in bitcoin's math - which you could have found in any other programming language anyway.
That said, a browser-based bitcoin client does expose its user to potential XSS exploits 'n such; especially if the private key is in the browser's memory.
1. https://en.bitcoin.it/wiki/Raw_Transactions , basically if you mess this stuff up you lose coins.