Processes run in a userspace and cannot do anything without OS approval.
For example GCP and AWS both have container running services. They both use hardware VMs to isolate different tenants. You will never share a kernel with another customer (I don't even think you will share one with yourself by default).
Container escape exploits are more common than VM escape exploits.