What I was inferring, and did not spell it out, is that it not the really the fault of the client, but must be malicious websites.
If the client side can cause the server to execute arbitrary code, then that is a bigger problem.
Because bad actors would never update their attacking platform.