a kernel exploit doesn't help you much with a docker style container. Also docker is not a VM. And iOS/Android are already way better with sandboxing than our desktop environments.
If one becomes root in a docker container, the worst damage it can do is to that container's files. That is better the current "sandboxing" in iOS/Android setup, true?