Re: We can't we just admit that sandboxes don't work?
It would change largely nothing. You would still be vulnerable to all sorts of things that are supposed to be pure non-executable data, but contain instructions carefully crafted to trip up the parsers that are supposed to display them to you.