Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can run Chromium inside a container or other outer sandbox, but that environment must still allow Chromium to create its own renderer sandbox. Chromium is already a multi-process, sandboxed browser. If the host blocks namespaces, seccomp or another required facility, startup can fail with No usable sandbox!. Adding --no-sandbox may hide the error, but it removes a major security boundary rather than fixing the deployment.

The short answer: there are two sandboxes, not one

When developers say they are “running Chromium in a sandbox,” they often mean a Linux container, a restricted service account or a platform sandbox around the browser process. Chromium has a separate, internal sandbox that it applies to renderer processes. The outer layer limits the browser from the host; the inner layer limits web content from the browser and operating system.

Those layers have different responsibilities. Chromium must be able to use an allowed kernel mechanism to create its renderer restrictions. A container policy that blocks that mechanism can prevent Chromium from starting, even though the process is already inside an environment called a sandbox.

The failure is therefore a compatibility problem between the host policy and Chromium’s security design, not proof that containers are useless or that Chromium is inherently unsandboxable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Acer Chromebook 2023 Flagship Laptop Computer Thin Light, 15.6” HD Display, Dual Core Intel Celeron N4020 (Upto 2.80 GHz), 4GB RAM, 64GB eMMC, Webcam, WiFi, Long Battery, Chrome OS+HubxcelAccessory
  • 【15.6" HD ANTI-GLARE DISPLAY】The large 15.6” HD display with an anti-glare coating and narrow 0.37-inch bezel gives users a greater workspace, so they can be more productive in bright conditions. HD 720p front-facing camera with built-in microphone. For Home, Student, Professionals, Small Business, School Education, and Commercial Enterprise. Online Class, Google Classroom Remote Learning, Zoom Ready.
  • 【DUAL-CORE INTEL CELERON N4020】Intel Celeron N4020 Processor (Base 1.1GHz, up to 2.8GHz, 2 Cores, 2 Threads). Featuring true machine intelligence and a newly designed efficient architecture, the groundbreaking processor learns and adapts to your needs so you can achieve more
  • 【4GB LPDDR4 SDRAM +64GB EMMC】Sufficient high-bandwidth 4GB RAM allows you to smoothly run your programs and browser tabs all at once. 64GB eMMC flash memory: This ultracompact memory system is ideal for mobile devices and applications, providing enhanced storage capabilities streamlined data management, quick boot-up times and support for high-definition video playback.
  • 【GOOGLE CHROME OS】 Designed for the modern world, Chromebook is your gateway to thousands of apps, complete with built-in protection and cloud backups. It excels in security, speed, regular updates, versatility, and user-friendly simplicity
  • 【SPECIFICS + 5-IN-1 VALUE PACK BUNDLE】14.42" L x 9.86" W x 0.8" H, 3.59 lbs; 2x USB 3.1 Type-C / 2x USB 3.1 Type-A / 1x Headphone/microphone combo; Wi-Fi 5 and Bluetooth combo; Silver;; Authorized HubxcelAccessories 5-in-1 Value Bundle: Includ Wireless Earbuds, Mouse Pad, HDMI Cable, USB Cable, Wireless Mouse for your daily work and life

What Chromium’s internal sandbox protects

Chromium is a multi-process application

Chromium separates the browser process from renderer processes and other supporting processes. Renderers process untrusted HTML, JavaScript, images and plug-ins. They do not need unrestricted direct access to the disk, network or devices, so Chromium can restrict them and require the browser process to mediate access through inter-process communication.

This architecture matters because a page can be malicious even when the URL was supplied by a trusted application. A renderer bug or a malicious script should not automatically grant the page the same access as the process coordinating the browser.

Linux uses several possible mechanisms

Chromium’s Linux sandbox can use setuid helpers, Linux namespaces and seccomp-BPF. Modern deployments commonly rely on namespaces and seccomp-BPF where the kernel and policy support them, but the exact mechanism depends on the browser build and host capabilities. There is no single switch that makes every Linux distribution equivalent.

Site Isolation is another layer

Site Isolation separates sites into different renderer processes and helps contain the consequences of a compromised renderer. It complements, rather than replaces, the renderer sandbox. The browser process, its privileged interfaces and the surrounding operating-system policy remain part of the overall security boundary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why an outer container can stop Chromium from starting

An outer sandbox is allowed to deny operations. Chromium’s inner sandbox needs some of those operations during startup. If the container runtime, seccomp profile, kernel configuration, user-namespace policy or distribution security policy denies a required operation, Chromium cannot establish the restrictions it expects for renderer processes.

Layer Primary job What can go wrong
Host kernel and distribution policy Provides and governs namespaces, seccomp and related primitives A required primitive is disabled or denied
Container or outer sandbox Restricts the browser process from the host Its profile blocks Chromium’s sandbox setup
Chromium browser process Coordinates renderers and mediates privileged operations Cannot create or communicate with restricted children
Renderer sandbox Limits processes handling untrusted web content Startup aborts if no supported mechanism is usable

Puppeteer documents this situation as the No usable sandbox! error and notes that host configuration can prevent Chrome for Testing from using user namespaces. The precise cause varies with the browser build, kernel, distribution, process privileges and container runtime; a recipe that works on one host is not a universal fix.

Rank #2
ASUS CHROMEBIT CS10 Stick-Desktop PC with RockChip 3288-C 2 GB LPDDR3L 16 GB eMMC Google Chrome OS
  • Plug in your way
  • Power and compatibility
  • Networking capabilities
  • Built-in security
  • Protecting your privacy

Why --no-sandbox is not a normal fix

The --no-sandbox launch argument tells Chromium not to use its sandbox. It can make a browser start in a constrained environment, but it does not repair the missing namespace, seccomp or privilege configuration. It removes the defense that limits what compromised renderer code can do.

Puppeteer’s troubleshooting guidance describes running without a sandbox as strongly discouraged and limits the exception to content the operator absolutely trusts. In an automation service that visits arbitrary URLs, “trusted” is a difficult assumption: redirects, third-party scripts and uploaded documents can all introduce content you did not author.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Do not add --no-sandbox merely because a copy-and-paste container example includes it.
  • Do not grant broad host privileges just to silence the error without documenting the resulting boundary.
  • If you must use the flag for a temporary, isolated test, keep the workload disposable, restrict its network and filesystem access, and remove the flag before production.

Diagnosing “No usable sandbox!”

1. Record the exact environment

Capture the Chromium or Chrome for Testing version, Linux distribution, kernel version, container runtime, user identity and launch arguments. The same error text can have different causes across these combinations.

chromium --version
uname -a
id
cat /proc/self/status | grep -E 'NoNewPrivs|Seccomp'

These commands do not prove that every sandbox mechanism is available, but they give you the facts needed to compare the host with the browser’s current documentation.

2. Check whether the process is running as root

Root execution changes which sandbox paths are available and is a common source of container-specific failures. Prefer a dedicated non-root user for browser automation. Make sure that user can read the browser files, write only to the intended temporary and profile directories, and access the fonts or other resources your job requires.

3. Inspect the container and service policy

Review the runtime’s seccomp profile, capability set, user-namespace policy and any distribution controls such as mandatory access-control rules. Look for denials in the container or host audit logs at the time Chromium starts. A denial there is more useful than repeatedly changing browser flags.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3

4. Verify the browser’s expected mechanism

Read the current Chromium Linux Sandbox documentation and your Puppeteer version’s troubleshooting page for the specific build. They describe which mechanisms are supported and which host configuration is required. Do not assume that a flag documented for one Chrome for Testing release applies unchanged to another.

5. Test with the browser sandbox enabled

Remove --no-sandbox and run a minimal launch as the same user and under the same service policy used in production. If it fails, preserve the complete stderr output and host-policy logs. If it succeeds only as a different user or outside the container, the difference identifies the boundary that needs correction.

Deployment approaches compared

Approach Host compatibility Isolation properties Privileges and constraints
Container with Chromium sandbox enabled Requires a kernel and runtime policy that allow Chromium’s chosen mechanism Outer container plus Chromium renderer sandbox Can run with a non-root user; profile design is operationally important
Restricted host or VM with Chromium sandbox enabled Usually easier to align because the browser sees a less restrictive kernel interface VM or host boundary plus Chromium sandbox Higher infrastructure cost or management overhead may apply
Container with --no-sandbox Often starts despite blocked browser primitives Outer boundary only; Chromium’s renderer defense is removed Risk depends on the outer policy and workload; strongly discouraged for untrusted content

No approach is universally best. Compare the kernel and policy compatibility, the isolation you retain, the privileges granted to the browser process and the operational limits of your deployment. Chromium’s own sandbox should be treated as an additional layer, not as a replacement for a container or VM.

A safer container checklist

  • Use a Chromium and automation-library version supported by your base image and kernel.
  • Run the browser as a dedicated non-root account.
  • Keep the Chromium sandbox enabled in the normal launch path.
  • Give the account a writable, size-limited temporary directory and browser profile; avoid exposing application secrets or the host filesystem.
  • Review seccomp, namespace and capability settings instead of weakening all of them.
  • Capture host audit logs when startup fails, then change one policy variable at a time.
  • Separate browser jobs from sensitive services and restrict outbound network access where the workload permits.
  • Retest after changing the kernel, base image, container runtime, browser build or automation library.

These controls do not turn an unsupported host into a supported one. They reduce exposure while you make the host and browser configuration compatible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When you do not need to operate Chromium yourself

If your goal is simply to obtain screenshots or PDFs, running a browser inside your own restricted environment may be unnecessary operational work. ScreenshotNeo provides a website screenshot API and MCP server, so your application or AI agent can request a capture without maintaining a Chromium container.

Or skip the browser setup

One GET request returns a PNG, JPEG, WebP or PDF. The API accepts a URL and an access key; the complete documentation is at https://screenshotneo.com/docs/.

Rank #4
HP Chromebook 14-inch FHD Laptop, Intel Celeron N4000, 4 GB RAM, 32 GB eMMC, Chrome (14a-na0050nr, Mineral Silver)
  • Google Play Store: The millions of Android apps you know and love on your phone and tablet can now run on your Chrome device without compromising their speed, simplicity or security
  • Environmentally conscious: Low halogen, mercury-free display backlights, arsenic-free display glass in this ENERGY STAR(R) certified, EPEAT(R) Silver registered Chromebook
  • Sleek, responsive design: Keep going comfortably with the backlit keyboard and multi-touch touchpad that supports four finger gestures set in a sleek design for moving from room to room or on the road

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing result with X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.

For occasional work, 1,000 screenshots per month are free with no card. Paid plans start at $5 for 3,000 screenshots; every feature is included on every plan. You can also control viewport and device presets, full-page and element capture, lazy-image loading, dark mode, retina scale, PDF paper and page ranges, custom CSS or JavaScript, clicks, waits, blocked requests, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed links, async webhooks, bulk capture of up to 100 URLs per call, usage data and the OpenAPI specification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create a free ScreenshotNeo account to get the 1,000 monthly captures without adding a card.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common failure modes and fixes

“No usable sandbox!” immediately after launch

Likely cause: the host or container denies every sandbox mechanism Chromium can use. Fix: compare the runtime policy and kernel capabilities with the current Chromium and Puppeteer requirements; run as the intended non-root user and inspect audit denials.

It works outside the container but not inside

Likely cause: a container seccomp profile, namespace setting or mandatory-access rule. Fix: diff the effective policies and privileges, then make the smallest documented adjustment that preserves the browser sandbox.

It works as root but fails as the service user

Likely cause: missing permissions for the sandbox helper, temporary directory or profile, or a policy that treats the users differently. Fix: correct ownership and directory permissions for the dedicated account and keep the non-root launch as the test that matters.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adding --no-sandbox makes it start

What it proves: only that bypassing Chromium’s internal sandbox avoids the blocked setup. Next step: remove the flag, identify the denied host operation and restore a supported sandbox path; do not treat the workaround as a production resolution for untrusted pages.

Best Value
115 In 1 Precision Screwdriver Set, Chromium Vanadium Steel Professional Repair Tool Kit for Computer, Watch, Camera, Mobile Phone, Laptop, Eyeglasses, Electronics, Etc (red)
  • Include: 115 pcs precision screwdriver set
  • Material: chromium vanadium steel
  • Application: professional repair tool kit for computer, watch, camera, mobile phone, laptop, eyeglasses, electronics, etc

The browser starts, but pages hang or crash

Likely cause: separate resource, network, shared-memory or profile restrictions. Fix: inspect browser stderr and container logs, verify that the service user has the required temporary/profile space, and test a minimal page before changing security flags.

FAQ

Does a Docker container automatically sandbox Chromium?

No. Docker or another container adds an outer boundary, while Chromium still needs to initialize its own renderer sandbox. The container can either add useful isolation or block the mechanisms Chromium requires.

Is the browser sandbox a substitute for a virtual machine?

No. Chromium’s sandbox limits renderer processes; a VM or host policy provides a separate isolation boundary around the entire guest or service. Defense in depth uses the layers together when the threat model warrants them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I safely disable the sandbox for a trusted internal page?

Only after assessing the complete workload and outer boundary. Puppeteer strongly discourages unsandboxed operation and limits it to content the operator absolutely trusts; redirects and third-party resources can invalidate that assumption.

Frequently Asked Questions

Does a Docker container automatically sandbox Chromium?

No. Docker or another container adds an outer boundary, while Chromium still needs to initialize its own renderer sandbox. The container can either add useful isolation or block the mechanisms Chromium requires.

Is the browser sandbox a substitute for a virtual machine?

No. Chromium’s sandbox limits renderer processes; a VM or host policy provides a separate isolation boundary around the entire guest or service. Defense in depth uses the layers together when the threat model warrants them.

Can I safely disable the sandbox for a trusted internal page?

Only after assessing the complete workload and outer boundary. Puppeteer strongly discourages unsandboxed operation and limits it to content the operator absolutely trusts; redirects and third-party resources can invalidate that assumption.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.