correct, but it limits the data they can exfiltrate. I can live more easily with my weather app downloading its upgrade patch over HTTP if there's a sandbox limiting what that hostile update will do when it lands.
The Linux kernel has had a lot of holes in the namespace stuff used for containers, I doubt that there will not be more. Not to mention all the local root exploits, seLinux-bypass, information leaks and so on. If you're relying on Linux features for security without at least using the grsec patches, you probably already lost.