There are a whole lot of web APIs that were developed without a care for privacy/security, that are slowwwwly being mitigated by Mozilla's resistFingerprinting and Tor Browser. Browsers certainly do more to get sandboxing right than native apps, but they aren't a panacea.