This is a pretty good illustration of the challenge of sandboxing: stipulate for a second that you could contain a browser exploit to a specific Unix UID (that's a very ambitious claim!) --- you're still left with a pretty big problem in this security model: the attacker might still be left with control of all your browser sessions.
For a big chunk of users --- perhaps the majority of all users --- this is all attackers actually want.