Earlier quoted context omitted.
That's research, never used in a real world attack. It's long since patched, and also that's not the WebHID API.
Moving goal posts. I guess all of this xz stuff is overblown because we do not have a documented case where it was used? Just research about something that might happen does not count, I guess. Here is a WebHID attack in Chrome with a 9.8 severity ( https://www.cve.news/cve-2023-1529/ )
The xz thing was a big deal precisely because it was a real world attack. It wasn't something created by researchers as a proof of concept and disclosed to vendors. It was discovered in the wild, luckily before it caused any damage, but it was absolutely a real world attack.