While problematic, this is pointing the finger at the wrong thing. The version of the browser was from 2024. The permutations of full chain exploits permitting sandbox escape since then is probably pretty high.
It's a patch gap, plain and simple. Removing the sandbox certainly did not help things.