Since Office 2016, Microsoft Office applications on macOS run in a restrictive sandbox that seeks to constrict the impact of any malicious code (such as macros).
However there have been several instances (such as [19] and [20]) where security researchers have found trivial sandbox escapes.
Interested in more information about macro-based attacks and sandbox escapes targeting macOS? See:
“Documents of Doom: Infecting macOS via Office Macros” [