They're weaponizable when using a small and rapidly shrinking percentage of unpatched browsers running JavaScript delivered by extremely uncommon websites.
>JavaScript delivered by extremely uncommon websites
All it takes it emailing them a slightly convincing link, and they're running javascript from one of those "extremely uncommon websites". It doesn't matter how common the website it, a single website can compromise millions of users.