Wine is not an emulator. It’s not sandboxed either. If you can do it as a user, a program running in wine can do it too.
There’s nothing stopping a piece of malware from crawling your disk for sensitive information, or encrypting your files for ransom.
I wouldn’t think so. Isn’t bottles just an easier way to manage wine prefixes? If so, it doesn’t do anything to hide your Linux system from the executable.
Wine prefixes are not sandboxes. They are a way to separate the windows-level configuration for different programs (eg env vars, or drivers, etc).
Wine is a translation layer between a compiled windows binary and your Linux syscalls/libraries/device drivers/etc, nothing more.