> Can you cite one real-world example of someone who's been infected using Firefox in newer times?
Coinbase was, and that wasn't long ago. If I were a sysadmin I'd blacklist Firefox from all my machines, no matter how I feel about the open web, about Mozilla or their mission statement, it's not a reasonable risk to take.
> Another counter-argument here is that people looking for vulnerabilities would much rather spend their time looking for chrome exploits than firefox exploits (because of market share), no?
People look for both. Firefox is a much higher value target to governments than Chrome, because that's what Tor Browser is.
Tor is Firefox ESR, which only has big security fixes backported; other security flaws remain in Firefox ESR for much longer. But beyond that, the security fundamentals were never a part of the original Firefox project like they were for Chrome, and it still isn't. 13 years later, Chrome's still making faster progress with exploit mitigation than Firefox, and Firefox is the one that needed catching up. There's a reason why GrapheneOS, which people here trust, don't use Firefox. Check their website for a great readup[0].
On Zerodium, Chrome RCE+LPE goes for $500k, Firefox and Safari. People will argue that's marketshare, but get any exploit mitigation researcher in here and they'll tell you Firefox (and Safari) are fundamentally less secure than Chrome. Price isn't just determined by demand (by governments), it's supply too.
I understand the "cyberpunk" love for Firefox, they're the good guys fighting big G. But that doesn't change what their codebase is.
[0]: https://grapheneos.org/usage#web-browsing