your command doesn't seem to set a memorymax on the browser unit, so oomploicy=stop probably won't do much. it might help to set the cap first, then the policy, and give each worker a unique unit name
you can check it with systemctl --user show on controlgroup, slice, memorymax and oompolicy. memory.oom.group isn't a systemd property, so that one you'd read from the sysfs folder for the controlgroup.
on the proxy lease post, execstoppost should still run after an oom kill, though it's worth testing on your systemd version. a host crash is the real hole there, so a lease ttl plus an independent reconciler is still a good idea