For example, if you allowed curl or Firefox, another executable can simply call one of them and send/receive whatever data they need to. It also can't do things like filter ptrace calls which could easily be used to modify another process to perform exfiltration or just spawn another thread and inject a whole new dynamic library to them, a common practice to bypass detection on Windows.
There is not need for explorer to access internet!
I only allow windows defender, firefox and chrome to access internet in my home computer setup all other apps are blocked unless truly needed.
If you block svchost.exe from internet access with windows firewall, it will block the windows update. Enable it once in a while to allow the windows update to go thru when you feel the need.
For instance if I type "firefox 'http://google.com'" in my terminal my already-running firefox instance loads the URL in a new tab, so I assume that some kind of IPC is used behind the scenes to ask the main instance to load the URL. Of course that's harder to exploit nefariously than spawning wget from the same process but when there's a will there's a way...
What overhead? `docker run --rm -it -v $PWD/untrustedprogram:/untrustedprogram:ro ubuntu:latest`, done. Use x11docker if needed.
Not sure if running a program as root in a container is the best approach to "fully sandbox" - depends on what the goal is, obviously.
With it you can write a security profile containing a rule like:
network tcp src 192.168.1.1:80 dst 170.1.1.0:80
Networking access is just the start, you can restrict many other stuff, like access to dbus, files, signals, etc.