>> A native app is less secure. They're all written in memory-unsafe languages, are not guaranteed to be up-to-date, and do not run sandboxed.
So how can we even trust the browser if native apps are always less secure according to you?
The exploit ran despite the sandbox if I understood it right.