Bugs exists. But JavaScript running in the browser have, theoretically, little access to anything. Definitely no FS access without user interactions, can’t access most of the system services, and the few that are accessible are through restricted API with permissions/confirmations.
The risk of allowing JavaScript on a website is more tied to the site data, or tracking. Rogue browser extensions are way more dangerous.
It doesn’t mean every site needs JavaScript, but having this enabled by default is not that big of a security risk for the system. It can help with phishing, though, if you don’t know what site you’re viewing.








If it ever take forms, it will be absolutely unenforceable with how many devices currently operates. Aside from a ban on open hardware (good luck with that), nothing will happen.
Unfortunately, being technically impossible to enforce is of little consequence. It just becomes a convenient law to pull out if they want to hammer you down and you happen to have a 3D printer that don’t have this built-in.