Good security has layers. That way if one falls through,
hopefully the next layer will catch it.
It's more a boundary for the browser not to pass because it has no business. I've seen an alternative approach which used a separate user account for Firefox and then SSH forwarding of X.