Look, it's very simple.
There are two ways you can design a browser:
(a) Allow the remote system unfettered access to the local system, so that it can, essentially, do as it likes.
(b) Deny the remote system access to the local system, so that, essentially, it doesn't matter what the remote...