Isn't this exactly why there is a sandbox? What can the RCE actually do or obtain within the sandbox?

Yes, it says right in the CVE

> allowed a remote attacker to execute arbitrary code *inside the sandbox*

[deleted]