Your average OS kernel has an abundance of interfaces, all of which may have bugs enabling a malicious program to elevate its privileges. The OS<->hypervisor channel can be much more restricted.
With containers, programs in the container are generally talking directly to the host kernel through the same interfaces as any other program, so you don't get that benefit.