This will not work without a complete analysis of all the DLLs before they are loaded (which is impossible in principle) or the creation of some magic at the same level as seccomp. Given any measures you take to restrict access, such as creating dummy kernel32.dll, a custom DLL may take countermeasures, such as loading DLLs that you have not considered, DLL calls that have been loaded by the host process (possibly through functions in the host application! ) or directly send Windows system calls.
Windows, Google Chrome - "sandbox". , , DLL . , Windows Chrome. , Google , "", - , , Windows.