You mean, you are catching exploits for vulnerabilities that don't exist anymore, and you pay for that with a gigantic attack surface that can be used to compromise you? Yeah, that sounds about right.
Bad example. Anti virus software is a scam. Just adds another attack vector when the anti virus software has a bug in their file parsing & makes it that you can be impacted by just downloading a malicious file
Windows Defender is sufficient & bundled with Windows
You're very close to understanding something.
(Though in defense of DOM purifiers they can use a whitelist)