Bridges act like a Switch not a dump Network-Hub.
As long as the bridge ageing isn't set to 0 it's not that easy to get onto the traffic.
Especcially for the VM's wich are connected with their own tun-Device to the bridge.
On the other hand, one could monitor traffic of a VM with connecting to its tun-Device.
But one has to sit on the host, not within a VM.