My position is just that browsers-in-VMs is a mostly roundabout threat model whose actual benefits (such as some semblance of filesystem isolation) can be achieved other ways.
What other ways would you recommend for filesystem isolation better than simply immutable VM running a web browser?