I don't see how https is relevant for browser JS vulnerabilities.
Man in the middle attacks are much easier.