Pretty much every aspect of video games already make them “handle everything with extreme caution”-type software- eg there were RCE bugs in tf2 that could be triggered by a malicious client joining a server, or being able to write whole programs into various pokemon gameboy games just using the right sequence of inputs. I think if I’m not mistaken there was even a case of user picture sprays in source engine games being maliciously crafted.
You may as well plan your security mitigations in such a way that, ultimately, RCE is no more of a big deal than somebody being able to launch notepad.exe or chrome.exe to use a cloud gpu server as a remote desktop.
Now, that’s all to be said unless you’re dealing w somebody who has a GPU-/hypervisor sandbox escape exploit in addition to a RCE sploit they want to plant. In which case ya ur screwed. And I bet there’s serious effort spent by both eg NVIDIA and other cloud gaming providers, but, well, that’s a different beast than untrusted binary savegames