While there is a way to blacklist bad data by banning the cert, there is currently no mechanism in iOS to purge association data from swcd once iOS has downloaded it. Furthermore, due to the cert used for association data signing being used in multiple places, blacklisting it would also blacklist the website and/or the app itself. That's going overboard as neither are malicious.
It's also wrong to say Windows has this solved. When the malicious FTDI drivers that intentionally bricked devices were delivered via Windows Update, Microsoft didn't pull them until FTDI requested it.
I'm not sure why you said "Apple can afford to beta test these issues". The bug was triggered by a specially crafted file, not arbitrary, generic data. That's why it's only known to occur with booking.com's data. It's hard to test for that, especially when the file is otherwise completely compliant JSON.
I'm not sure what you think the "simple" fix is, purging keychain data on crash isn't easy.
The fact it was booking.com's data was only discovered yesterday, which is also when I filed a security bug with Apple. Although Apple did approve a fixed version of Booking.com (for new users) for the App Store extremely quickly as an emergency exception.
Google search results are disabled because of how Google uses JavaScript to open URLs. Their method of opening URLs forces the link to go through swcd To check if it's a Universal Link. That's also why disabling JavaScript fixes it for Google but "Open in Safari" and links from Mail continue to die.