Earlier quoted context omitted.
What if the website told the browser to load malware? Browsers in the modern web need to defend the user, not execute arbitrary instructions from random websites that nobody cares about.
A website cannot tell a browser to "load malware", unless we're talking about a exploit, which should be patched. (Please don't say "if I send you a malformed png file you have to execute the exploit, otherwise your argument breaks down".)
You are covering the unauthorized access but disrupting/damaging is absolutely possible using plain old HTML and JS.
Privacy advocates argue that it's not only possible but many trackers are guilty of exactly that.
So the browser is in fact blocking malware.
... And yes, if you think about it, that definition does apply to ads as well. Really says something doesn't it :)