Heck, glibc by default still allows LD_PRELOAD pretty much everywhere, and most distros have available SUID binaries you can hijack, so it's useless sandboxing anyways.
Setting aside the absurd amount of self invented config file formats for it (which have so many pitfalls for endusers) I think that firejail is the only viable alternative as a seccomp sandbox.
Flatpak's sandbox approach is as useless as AppArmor's approach, nobody can use it because the people that design it seemingly never use it in production apart from their www user test cases. If you try to sandbox a complicated program like Firefox with its hundreds of rendering processes, well, good luck...we'll talk two days later on how much progress you made just creating the config files.
I got so pissed by all of it that I started to learn eBPF to build a better sandbox, which I am trying to combine with a smart firewalling approach. But honestly, it's a ton of work, and the lack of profiles for everything makes it really hard to get to production.
You literally need to implement something like a "learning mode" that test runs a program, just to figure out what you want to allow or deny. This approach kinda worked for me, but I am now literally writing a DNS filter because resolv.conf as a concept is pretty much useless as well.
Once you start building something like this you see yourself 2 years later implementing all kinds of network services which in themselves are attack surfaces already...so you start to question whether it is really all worth it. Even hooking something as "simple" as DNS resolver API calls becomes a task that is a shitload of work until completed.