You need to make sure that opt franz chrome sandbox is owned by root and has mode 4755 code example
Example: The SUID sandbox helper binary was found, but is not configured correctly.
sysctl kernel.unprivileged_userns_clone=1
sysctl kernel.unprivileged_userns_clone=1