Flatpak is handy, but given their history, if I can run it in the browser, I'll leave it there. I don't want it, even in a sandbox.
Check out these CVEs: * https://nvd.nist.gov/vuln/detail/CVE-2025-49457 * https://nvd.nist.gov/vuln/detail/CVE-2026-22844