These are Linux containers in a VM, I’m pretty sure GP is talking about native macOS containers.
Which: They do actually have some container-like sandboxing tech around applications (“iTerm wants to access your downloads folder”).
Which: They do actually have some container-like sandboxing tech around applications (“iTerm wants to access your downloads folder”).
https://bdash.net.nz/posts/tcc-and-the-platform-sandbox-poli... and https://bdash.net.nz/posts/sandboxing-on-macos/ are good introductory articles.