Does this mean we have to run vlc in a sandbox while watching a downloaded film?

In production? With a user-supplied film?

You seem to be captured by the “all or nothing” security fallacy, when security must be viewed through the lens of (probability) x (impact)