Phishing / malicious site redirects

A

AC Question

Hi,

Samsung S7; everything stock, up to date firmware and security policy, never allowed 3rd party apps, no sideloading etc. totally vanilla usage.

Sometimes I accidentally click on ads while scrolling in Chrome, or promoted tweets (ads) in Twitter, especially when the ad loads and adjusts the formatting of the page just as I release my finger from the screen.

Other than 'legitimate' ads (still annoying) or click generators (e.g. Outbrain) sometimes it's a phishing site or similar, e.g. '1 Virus(es) Detected'/'Optimize Your Device' or a fake login page. Whatever, I click back and continue browsing.

However, this time, in addition to a fake 'You've Won, Fill Out This Quiz' asking for Google account information a popup came up like a system notification dialog box (like when you've finished updating firmware) with a spiel about having won a prize yadda yadda. I backed out immediately naturally, but this was new

Am I correct in thinking that, barring some incredible day-zero exploit or similar, my phone is fine? It's not possible to do a drive by download or script injector like in the old days?

Related question: is there a more secure (unrooted) way to browse the internet on Android? After years of noscript and ABP on PC browsing the internet on Android doesn't feel good.

Thanks for your input in advance, it is much appreciated.