> Wasn't the main reason that it was really difficult to keep the sandbox secure?

It basically ran JavaScript. It's no harder to sandbox Flash than it's to sandbox any HTML5 website. Arguably much easier because there was no JIT back then. Flash also ran in an enclosed box on a website and had no access to DOM, which greatly lowers attack surface.