- defense in depth means adding such an extra layer is a good idea
- an app can 100% stay within its sandbox and still be nefarious. For example, a password manager could secretly send all your passwords to Mr(s) Evil.
With a proper sandbox, a password manager won't have internet access.
With a proper sandbox, a password manager won't have internet access.