I said this at the time

It's not a secret that they're running a JavaScript interpreter in a system security context for performance reasons.

Therefore they are never going to run out of vulnerabilities that allow remote code execution in a system security context.

