Some vehicle systems use a VNC compatible client for this. Essentially put the "web parts" into their own system entirely, even physically, and then project the results into a window on the "safe part" UI. If something bad happens the VNC server might crash and client lose connection, but that's the limit of the danger.
I know around the time Carplay became popular several auto manufacturers were pushing this idea as a Carplay/Android Auto alternative implementation: glorified VNC. But I guess the data wasn't "rich" enough for some parties.
There is a separate computer system. On the S the separate computer system for the drive train has its own screen (in front of the driver). On the 3 they use one display. you can separately reboot the non-drivetrain one.