But how do they prevent an attacker from simply opening his own connection? They can just look up the keys in the other processes.
I'm not sure what Firefox does, I believe they use the Chromium sandbox, and I'm way out of date on that. It used to do some filesystem setup like hardened chroots, but I would assume that's been supplanted by fs namespacing.