@KekunPlazas @tbernard This is one big reason why I've been experimenting so much on the side with running browsers inside bwrap so I could have a persistent but externally-sandboxed browser for more trusted browsing, and a disposable sandboxed browser that erased its sandbox when the window closed, for untrusted browsing (like opening URLs from external sources).
The implementation is pretty simple, it's just a matter of maintaining bwrap rules long-term.