Show- If you are using my settings sandboxing the browsers is not necessary (but you can still do so if you choose).
Understand that in order for an infected webpage to infect your system (either through an exploit kit or through some script), something MUST be downloaded (perhaps without you knowledge) and be able to run locally on your computer. It is this, and any other, action that will be detected by CF and automatically will be shunted into the sandbox, thus affording you protection.
What Bribon stated above is totally correct- if you use my settings AND sandbox the browser the browser will not connect out. But NEVER EVER change the setting that stops sandboxed processes from connecting out (SBIE also has a similar setting), as this setting stops things like Keyloggers, Bankers, and diverse other info stealers from sending any stolen info to the Blackhats (personally I could care less what info a malware file collects as long as it cannot do a God Damned thing with it); also having sandboxed processes precluded from connecting out will stop other malware in their nasty tracks- an example here is the recent GrandCrab ransomware- once the malware sees it cannot connect to its server it just shuts off.
But to make a long post even longer, you really don't have to worry about sandboxing the browser with CF; you can jump through unneeded hops to make it so, but why bother? Life is too precious to waste time...