“Sandboxing protects the system by limiting the kinds of operations an application can perform, such as opening documents or accessing the network. Sandboxing makes it more difficult for a security threat to take advantage of an issue in a specific application to affect the greater system.”
Thank you Apple – I’ve been waiting for this since hearing about its creation for Linux. Read more about Lion here.