There's a reason for defender even with a sandboxed app. Exploiting the sandboxed app may not allow the virus to access other parts of the system, but it still allows messing with the apps memory and spreading online (you likely got it from an app with network permissions in the first place)