The frustrating part is that Snap's confinement story was supposed to be a selling point. Here we are with a priv-esc in the daemon itself. At this point I've just disabled snapd on all our Ubuntu boxes and moved to flatpak or building from source. The attack surface of a privileged install daemon that parses arbitrary package manifests is just too broad.
Then you need to plan a migration away from Ubuntu, as Canonical is embedding Snap so deep in 26.04 it probably won't be usable with snapd disabled, e.g. no sound because Pipewire will be shipped as a snap. That's why I started experimenting with CachyOS.