I usually use a grsec-patched kernel, which helps prevent a number of theoretical exploits, e.g. permission escalation. It doesn't sandbox software but I think it must prevent similar exploits to Firejail.

Reply via email to