I'm afraid of the sky falling (it is).
Somehow, I must've missed all these cases where bad actors abused the WebUSB API. So what did they do? What's the worst damage the victims have suffered?
That's general - in this specific case, by my reckoning, it can never be safe for a website to understand, in any depth, the hardware of the machine requesting it.
You still haven't explained: why? When the options are "website" or "untrusted binary", the website is objectively much safer. Sure, you can sandbox untrusted binaries - but then you can just sandbox the browser.
Yes, there are security concerns, but these fears haven't been confirmed in real life, and they don't disappear if we ban WebUSB! Instead, people have to run untrusted code with access to far more hardware than WebUSB allows.