Are partial exploits (e.g. browser RCE w/o sandbox escape) eligible?

Yes. We can acquire either individual exploits (e.g. a browser RCE without a sandbox escape or a sandbox escape alone without any browser exploit) or chained/combined exploits.