All doors are open for side channel leaks. Having programs run on your machine is like having someone watch your computer. The issue is how to control the exfiltration of that data from you computer. That's where the sandbox should be focused on.
Ideally cross-origin framing would have been disallowed by default but frames were added to the spec before people spent a lot of time thinking about the same-origin-policy implications.
[0]: https://www.contextis.com/resources/white-papers/pixel-perfe... [1]: http://blog.saynotolinux.com/blog/2014/02/05/whats-that-smel...