If anything it will reduce the security nightmare.
It's not just a matter of technical difficulty, but also a problem of getting users on board: lots of them look at Flathub and -- quite understandably -- wonder why you'd want to jump through fifty sandboxing hoops to sandbox applications like Gimp and VLC, whose developers they trust and for which they get sandboxed packages out of their distributions' repos. The obvious retort that this isn't aimed at applications like Gimp and VLC feels a bit unsubstantiated because... what applications is it actually aimed at, then? Closed-source, potentially malicious applications like... what, if Linux had a lot of those, "the year of Linux on the desktop" wouldn't be a joke. And why not just run those in a virtual machine, which is likely to be a lot harder to escape from and also means you get to keep a "normal" *nix system as a host.
It's hard to get people on-board with sandboxing when most of them shrug and say they don't need it, and when -- if you squint a little -- it kindda turns out they're not entirely wrong, either.
Meltdown should have been the nail in the coffin for this philosophy.
To mitigate zero-day vulnerabilities in applications that parse external data (such as Gimp and VLC)? Trusting an application does not mean that it does not have vulnerabilities that can be exploited in the future.
> for which they get sandboxed packages out of their distributions' repos
s/sandboxed/signed)