Earlier quoted context omitted.
Yes. If that wasn't the case, then "HTML virus" would be a thing: I send you an HTML file and, if you open it, it read files from your hard drive and uploads them to my server.
The problem with your scenario is the reading the local files without permission, not the use of the crypto API.
I'm pretty sure Brave was blocking window.crypto but can't remember if it was on a file or over plain HTTP