> Vanilla js running on webpages should be considered relatively safe. It's sandboxed and not able to do anything - malicious of not - outside it's restricted environment.
The number of exploits requiring JS versus the number of exploits not requiring JS seriously disagrees with that opinion.
JS is a dynamic language that browsers put a lot of effort into JITting to be fast and limiting memory usage. And as such, the engines are complex. And as such, it's inherently hard to keep safe.
The v8 engine has literally over a million lines of code.
> If you could somehow disable all logic from executing in your OS native apps, would you do this by default?
Yes. And I actually do this on a regular basis. There are a lot of things I'll only run in a VM, or run in a VM the first time to see what it's attempting to communicate with / do (and occasionally block said communication for later). Not perfect, but better than nothing.