This is a fluff piece that has zero technical details. But I find your logic very interesting: if the presence of one CVE in sandboxing makes sandboxing untrustworthy, should we not have long ago discounted the entire security of Linux due to many CVEs for privilege escalation? Or the security of any and all browsers?
No.
But we probably should not think "There are several ways using only the GUI to tell whether an app is sandboxed.".
Let's not be that OpenAI guy.