I can guarantee you that the sandbox can be circumvented if you can just run an IPA on the device. iOS has a humongous set of APIs and that attack surface is impossible to protect properly.
Don’t get me wrong, I’d love to have an iPhone I can install anything on - but there is _no_ way I would ever install anything from the open internet on the same device use to read my email or log in to my bank.