The API exists because zoom.com request microphone and camera through an iframe is a legit use case. As OP said below CSPs exist so that enterprises can lock down those vulnerabilities. But wouldn’t make sense to lock it down for all consumers.
Sandbox is provided through things like ContentSecurityPolicy and Feature Policies. See my comment on this.