It'd like to broaden this question: Why is there almost nowhere a straight-forward option to limit network access?
Even backend app containers like Docker, which are all about restricting permissions and maintaining a sandbox, allow arbitrary outgoing connections by default.