That's why both Mozilla and Google have predicated their JXL support on a memory-safe implementation. There's a Rust one in the works.
I think Google are aiming to replace all of Chromiums decoders with memory-safe ones anyway, even for relatively simple formats.
If that's their plan, I predict another situation exactly like this one where Google decides that removing support is the best move forward. Careful, BMP, Chrome is out to get you!