I think the takeaway here is that there's likely more of these kind of vulnerabilities that's not discovered and VSCode should run in a sandbox or separate virtual machine.
No, because VSCode is used for producing new software.
1. Any newly written code would need additional vetting to permit it to run outside the original sandbox.
2. Industrial espionage. In particular, the attacker would immediately see any vulnerability in the making.