How about you all slowly wean off this utterly dumb habit of ranting and raving about your pet problems in unrelated topics?
For linux there's a couple ways of setting up a process group that can't access your network.
I'm not very familiar with other OSes.
Why do you ask? Isolation between processes can be difficult on non-phone operating systems, but removing permissions tends to be quite easy.
docker run --network none