They can’t have
their own JIT. If you use SFSafariViewController or WKWebView you’re using Safari and it’s standard JIT. But you have no access to it outside normal JS so it’s no more exploitable than the Safari app would be.
I believe the JIT runs in its own process too.