JS is not the only attack surface in a browser. There have been exploitable bugs in image parsers, font renderers, etc. Tracking is possible without JS as well.
I used to do this on linux, as I had copies of my windows VM and I would just browse from the windows box on another screen and then work from the linux one on the main screen
Maybe try lynx?