> In the extreme case you could open a new, non-persistent browser session for every page you visit.

This is seamless on Qubes OS: You just click a link and a new empty VM with Firefox opens. You close the browser, and the VM is destroyed. Can't recommend it enough.

Not really sure that’s safe. There has been at least 1 Qubes OS specific VM escapes this year and 2 KVM guest->host control ones.

There were only two VM escapes from Qubes OS in the last 20 years [0]. How is this not sufficiently secure?

[0] https://forum.qubes-os.org/t/qsb-116-multiple-xen-issues-xsa...