There's absolutely no evidence that this has anything to do with Flash. In fact, even if it was via Flash, there would still have to be another vulnerability to escape the Chrome sandbox, which could very likely be exploited via other means.
I don't see how Flash can be the culprit or solution considering it is sandboxed. Chrome must contain a massive exploit.
I thought the point was that they broke the sandboxing.
Sadly, one aspect of security is psychological acceptability. If nobody will do the secure thing, it's not secure.