Yes you are safe with your userland apps. And Ubuntu took care of firefox which use snap and apparmor. And there is flatpak of course.
And you have systemd 'jail configurations' to protect some systemd daemons - for example look inside systemd-resolved.conf.(which handles DNS queries) You can enhance some daemon conf's by addinig more restrictions - like 'ProtectHome' ( if i remember correctly), (the options are documented in systemd something)
But Ubuntu is lying with those empty apparmor placeholder profilles, it makes the apparmor 'status' command shows a long list of stuff. And I don't like them lying. You lose a bit of faith with them.