http://www.eweek.com/security/pwn2own-hacking-contest-return...
mentions:
"We wanted to focus on the browsers that have made serious security improvements in the last year," Gorenc said.
http://www.eweek.com/security/pwn2own-hacking-contest-return...
mentions:
"We wanted to focus on the browsers that have made serious security improvements in the last year," Gorenc said.
This claim is oft repeated, but the only reasons people seem to say it is that multiprocess + sandbox is not in release Firefox (it's in Nightly/Aurora/Beta).
That doesn't necessarily make it true. There's been some blogs since about how the JS <-> C++ sandbox has actually been significantly strengthened, but people just ignore truths that don't fit their preconceptions.
IE/Edge and Chrome also have sandboxes, and they still get cracked every Pwn2Own.
Normal people don't install development versions.
A sandbox isn't full proof, but it is way better than not having anything.