>>108254295
$ stat /usr/lib64/chromium-browser/chrome-sandbox
File: /usr/lib64/chromium-browser/chrome-sandbox
Size: 24152 Blocks: 48 IO Block: 4096 regular file
Device: 8,2 Inode: 7217772 Links: 1
Access: (4755/-rwsr-xr-x) Uid: ( 0/ root) Gid: ( 0/ root)
Notice the +s bit?
>>108254300
They would say that because they're delusional schizophrenics that think running binaries as root is perfectly OK when they do it. Security to them is all about how much privilege the sandbox process has to contain everything. They aren't thinking from a system perspective of "What happens if my sandbox process has a bug that leaks all of these privileges".