[1] https://firejail.wordpress.com/
[2] https://firejail.wordpress.com/documentation-2/firefox-guide...
I think in this case though where you're more concerned about the very real problem of websites accessing localhost, it probably outweighs the maybe of a firejail exploit.
These tools often drop privileges as soon as the program is executed, in firejail, there's also an option to disalble root entirely within a namespace.
https://blog.jessfraz.com/post/docker-containers-on-the-desk...