Except that most machines have arbitrary remote code execution via JavaScript in browser. I don't know how easily that can be exploited, but I wouldn't be surprised if ignoring the potential of this happening would bite us in the backside at some point.