Consider that any Mac app that:
* Supports plugins that aren't signed by Apple
* Executes scripts or macros from a file
would technically have the same "problem". That's a heck of a lot of apps.
On iOS Apple do insist on a full chain of security, which is why only Apple's own browser app can JIT code. It's an extremely perverse and serious limitation that has no real security justification: consider that Android manages just fine without it.
As far as I can tell, Zoom is currently the target of a witchhunt. People are digging for dirt and blowing stuff well out of proportion.