For all users reading this on their own home network: DISABLE ALL GUEST NETWORKS

It seems as if approved guest access now == system-wide access (at the hardware level). User compartmentalization no longer works.

Is this still true if the guest network is on its own isolated vlan?

Correct; this appears to be a hardware-level problem.