One of the biggest sources of browser security flaws was browsers during that era, also. Moreover browser makers had access to the Flash source code, and Flash was an open spec anyone could implement.
I don't think it's as simple as "web secure, everything else bad". For the very longest time only Chrome and Safari had working sandboxes, and there wasn't a huge difference in the exploit stream between WebKit, Flash, Java and Adobe Reader. They all had somewhat similar feature sets.
I don't think it's as simple as "web secure, everything else bad". For the very longest time only Chrome and Safari had working sandboxes, and there wasn't a huge difference in the exploit stream between WebKit, Flash, Java and Adobe Reader. They all had somewhat similar feature sets.